# CVE-2026-44947

## Summary

- **CVE ID:** CVE-2026-44947
- **Severity:** MEDIUM
- **CVSS Score:** 6.9 (CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N)
- **CWE:** CWE-281
- **Published:** Jun 30, 2026
- **Last Modified:** Jun 30, 2026

## Description

A missing clean-up in the legacy Project Role Template Binding (PRTB) 
reconciler in Rancher versions 2.13.0 up to 2.13.7 and 2.14.0 up to 2.14.3 allowed users to retain unauthorized Pod Security 
Admission (PSA) permissions after an administrator removes those 
permissions from a RoleTemplate.

## Affected Products

- SUSE — Rancher (2.13.0)
- SUSE — Rancher (2.14.0)

## References

- [CNA](https://github.com/rancher/rancher/security/advisories/GHSA-c4rp-wgqc-mfhc)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.39%
- **EPSS Percentile:** 32.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._