CVE-2026-75035 UNKNOWN

CVE-2026-75035

Published: 2026-09-03

Description

A flaw was found in Rancher Manager. When a non-administrative caller supplied a label selector naming a different user, the ext.cattle.io/v1 Token store dropped its internal owner filter instead of returning an empty result. Any authenticated user could therefore list and watch every other user's tokens, disclosing token metadata and the stored salted hash of the bearer token. This issue affects Rancher: before 2.15.1.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…