CVE-2026-75035

A flaw was found in Rancher Manager. When a non-administrative caller supplied a label selector naming a different user, the ext.cattle.io/v1 Token store dropped its internal owner filter instead of returning an empty result. Any authenticated user could therefore list and watch every other user's tokens, disclosing token metadata and the stored salted hash of the bearer token. This issue affects Rancher: before 2.15.1.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-03 16:18

Updated : 2026-09-05 02:17


NVD link : CVE-2026-75035

Mitre link : CVE-2026-75035

CVE.ORG link : CVE-2026-75035


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key