CVE-2026-44947: Suse Rancher
Medium severity, CVSS 6.9. EPSS: 0.4% chance of exploitation in the next 30 days.
A missing clean-up in the legacy Project Role Template Binding (PRTB) reconciler in Rancher versions 2.13.0 up to 2.13.7 and 2.14.0 up to 2.14.3 allowed users to retain unauthorized Pod Security Admission (PSA) permissions after an administrator removes those permissions from a RoleTemplate.
Affected products
- Suse Rancher: from 2.13.0, before 2.13.7 (fixed in 2.13.7); from 2.14.0, before 2.14.3 (fixed in 2.14.3)
Published 2026-06-30. Last modified 2026-07-02.