CyberRota Analysis
AI-GeneratedRancher Manager versions prior to 2.15.1 are vulnerable due to inadequate SAML assertion replay protection, which allows an attacker to exploit captured assertion IDs across multiple replicas in high-availability deployments. This flaw enables the attacker to gain unauthorized access by replaying assertions, potentially leading to multiple authenticated sessions as the victim. Organizations using Rancher in high-availability configurations should prioritize patching to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A flaw was found in Rancher Manager. The SAML assertion replay protection introduced by the fix for CVE-2026-44946 recorded consumed assertion IDs in a per-process cache, so each replica only detected replays that reached the same pod. In a high-availability deployment, an attacker holding a captured assertion could replay it once against every other replica to obtain additional authenticated sessions as the victim. This issue affects Rancher: before 2.15.1.