SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-75035

HIGH · CVSS 7.7 EPSS 0.20% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-03 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A vulnerability in Rancher Manager allows any authenticated user to bypass internal owner filters when supplying a label selector for a different user, enabling them to list and watch all other users' tokens. This exposure can lead to the disclosure of sensitive token metadata and the salted hash of bearer tokens, posing a significant risk to user privacy and security. Organizations using Rancher versions prior to 2.15.1 should prioritize patching this flaw to mitigate potential unauthorized access to user tokens.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-75035
Severity
HIGH
CVSS
7.7
EPSS
0.20%

Original NVD Description

A flaw was found in Rancher Manager. When a non-administrative caller supplied a label selector naming a different user, the ext.cattle.io/v1 Token store dropped its internal owner filter instead of returning an empty result. Any authenticated user could therefore list and watch every other user's tokens, disclosing token metadata and the stored salted hash of the bearer token. This issue affects Rancher: before 2.15.1.