A flaw was found in Rancher Manager. Project Secrets were propagated into a namespace based only on its `field.cattle.io/projectId` annotation, without verifying that the referenced project belonged to the same downstream cluster. A user able to create namespaces on one cluster could set the annotation to a project ID from another cluster and have that project's secrets copied into a namespace under their control.
This issue affects Rancher: before 2.15.1.
References
| Link | Resource |
|---|---|
| https://github.com/rancher/rancher/releases/tag/v2.15.1 |
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-03 15:17
Updated : 2026-09-08 19:12
NVD link : CVE-2026-75033
Mitre link : CVE-2026-75033
CVE.ORG link : CVE-2026-75033
JSON object : View
Products Affected
No product.
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
