High severity7.7NVD Advisory· Published Sep 3, 2026· Updated Sep 3, 2026
CVE-2026-75033
CVE-2026-75033
Description
A flaw was found in Rancher Manager. Project Secrets were propagated into a namespace based only on its field.cattle.io/projectId annotation, without verifying that the referenced project belonged to the same downstream cluster. A user able to create namespaces on one cluster could set the annotation to a project ID from another cluster and have that project's secrets copied into a namespace under their control.
This issue affects Rancher: before 2.15.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: <2.15.1
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.