PT-2026-83116 · Suse · Rancher
CVE-2026-75035
·
Published
2026-08-28
·
Updated
2026-09-03
CVSS v3.1
7.7
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Rancher versions prior to 2.15.1
Description
A flaw in Rancher Manager allows an authenticated non-administrative user to list and watch tokens belonging to other users. This occurs when a label selector naming a different user is supplied, causing the 'ext.cattle.io/v1' Token store to drop its internal owner filter instead of returning an empty result. This leads to the disclosure of token metadata and the stored salted hash of the bearer token.
Recommendations
Update to version 2.15.1 or later.
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rancher