CVE-2026-75034

HIGH CVSS 3.1: 7.4 EPSS 0.20%
Updated Sep 18, 2026
Suse
Parameter Value
CVSS 7.4 (HIGH)
Affected Versions before 2.15.1
Fixed In 2.15.1
Type CWE-294 (Authentication Bypass by Capture-Replay)
Vendor Suse
Public PoC No

A flaw was found in Rancher Manager. The SAML assertion replay protection introduced by the fix for CVE-2026-44946 recorded consumed assertion IDs in a per-process cache, so each replica only detected replays that reached the same pod. In a high-availability deployment, an attacker holding a captured assertion could replay it once against every other replica to obtain additional authenticated sessions as the victim.

This issue affects Rancher: before 2.15.1.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
High
Difficult to exploit
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
None
No disruption

CVSS Vector v3.1

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Suse Rancher
cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
2.15.1