PT-2026-85055 · Suse · Rancher
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N |
A flaw was found in Rancher Manager. The /v3/users update path did not enforce immutability of a User resource's
username and principalIds fields. A user holding the update verb on users.management.cattle.io could inject a foreign identity provider principal into any account, so that the next login by the owner of that principal was bound to the victim's account and inherited its role bindings.This issue affects Rancher: before 2.15.1.
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rancher