← Terug naar overzicht

A security flaw was identified in Rancher Manager where the ext.cattle.io/v1 Token store improperly drops its internal owner filter when a non-administrative user supplies a label selector referencing a different user. This logic error allows any authenticated user to list and watch all other users' tokens without restriction. The vulnerability exposes token metadata and stored salted hashes of bearer tokens, which could be leveraged for further attacks. The flaw affects all Rancher versions prior to 2.15.1 and is classified as a high-severity information disclosure issue. A fix has been released in Rancher v2.15.1. Organizations running Rancher should update immediately to mitigate the risk of unauthorized token access and potential privilege escalation.

Affected products

  • Rancher Manager
  • Rancher before 2.15.1

Related CVE's

  • CVE-2026-75035

Categories

  • Cloud & Virtualization
  • Data Breach & Exfiltration
  • Identity & Access