SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-75033

HIGH · CVSS 7.7 EPSS 0.21% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-03 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A vulnerability in Rancher Manager allows users to exploit the `field.cattle.io/projectId` annotation to propagate project secrets into unauthorized namespaces across different clusters. This could lead to unauthorized access to sensitive information, as an attacker with the ability to create namespaces can manipulate project IDs to access secrets from other clusters. Organizations using Rancher versions prior to 2.15.1 should prioritize patching this issue to mitigate potential data breaches.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-75033
Severity
HIGH
CVSS
7.7
EPSS
0.21%

Original NVD Description

A flaw was found in Rancher Manager. Project Secrets were propagated into a namespace based only on its `field.cattle.io/projectId` annotation, without verifying that the referenced project belonged to the same downstream cluster. A user able to create namespaces on one cluster could set the annotation to a project ID from another cluster and have that project's secrets copied into a namespace under their control. This issue affects Rancher: before 2.15.1.