Executive brief
Rancher, a popular platform for managing Kubernetes clusters, is affected by a security flaw in how it handles SAML-based logins (such as Okta, Ping, or Keycloak). An attacker who intercepts a user's login data can reuse that information to create their own session, effectively impersonating the victim. This could allow an unauthorized person to gain full administrative control over the Rancher environment and the managed infrastructure.
Technical details
A capture-replay vulnerability (CWE-294) exists in Rancher's shared SAML Assertion Consumer Service (ACS) handler within 'pkg/auth/providers/saml/saml_client.go'. The application fails to enforce one-time use of SAML assertions, allowing a previously signed SAML response to be submitted multiple times. To exploit this, an attacker must obtain a valid signed SAML response and the corresponding pre-authentication state cookie (e.g., via network interception or XSS). Successful exploitation results in full session impersonation with the victim's privileges. The fix introduces server-side tracking of assertion IDs in an in-memory cache and enforces strict NotBefore/NotOnOrAfter time validation.
Affected products
- SUSE Rancher >=2.11.0, <2.11.15
- SUSE Rancher >=2.12.0, <2.12.11
- SUSE Rancher >=2.13.0, <2.13.7
- SUSE Rancher >=2.14.0, <2.14.3
Timeline
- 2026-06-29: advisory: GitHub advisory published by Rancher team
- 2026-06-30: disclosed: NVD publication date