PT-2026-83116 · Suse · Rancher

CVE-2026-75035

·

Published

2026-08-28

·

Updated

2026-09-03

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Rancher versions prior to 2.15.1
Description A flaw in Rancher Manager allows an authenticated non-administrative user to list and watch tokens belonging to other users. This occurs when a label selector naming a different user is supplied, causing the 'ext.cattle.io/v1' Token store to drop its internal owner filter instead of returning an empty result. This leads to the disclosure of token metadata and the stored salted hash of the bearer token.
Recommendations Update to version 2.15.1 or later.

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-75035

Affected Products

Rancher