A security flaw was discovered in Rancher Manager where Project Secrets were propagated into namespaces based solely on the `field.cattle.io/projectId` annotation without verifying that the referenced project belonged to the same downstream cluster. This allowed a malicious user with namespace creation privileges on one cluster to set the annotation to a project ID from a different cluster, causing that project's secrets to be copied into a namespace they control. The vulnerability represents an unauthorized cross-cluster secret access issue that could expose sensitive credentials and configuration data. The flaw affects all Rancher versions prior to 2.15.1. A patch has been released in Rancher version 2.15.1. Organizations running multi-cluster Rancher environments are particularly at risk as this could allow lateral movement between clusters. Users should upgrade to version 2.15.1 or later immediately.