← Back to overview

A security flaw was discovered in Rancher Manager where Project Secrets were propagated into namespaces based solely on the `field.cattle.io/projectId` annotation without verifying that the referenced project belonged to the same downstream cluster. This allowed a malicious user with namespace creation privileges on one cluster to set the annotation to a project ID from a different cluster, causing that project's secrets to be copied into a namespace they control. The vulnerability represents an unauthorized cross-cluster secret access issue that could expose sensitive credentials and configuration data. The flaw affects all Rancher versions prior to 2.15.1. A patch has been released in Rancher version 2.15.1. Organizations running multi-cluster Rancher environments are particularly at risk as this could allow lateral movement between clusters. Users should upgrade to version 2.15.1 or later immediately.

Affected products

  • Rancher Manager

Related CVE's

  • CVE-2026-75033

Categories

  • Cloud & Virtualization
  • Data Breach & Exfiltration
  • Identity & Access