This issue affects Rancher: before 2.15.1.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://github.com/rancher/rancher/releases/tag/v2.15.1 |
|
Thu, 03 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 03 Sep 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Rancher Manager. Project Secrets were propagated into a namespace based only on its `field.cattle.io/projectId` annotation, without verifying that the referenced project belonged to the same downstream cluster. A user able to create namespaces on one cluster could set the annotation to a project ID from another cluster and have that project's secrets copied into a namespace under their control. This issue affects Rancher: before 2.15.1. | |
| Title | Rancher: Cross-Cluster Secret Leakage via Namespace projectId Annotation Spoofing | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: suse
Published:
Updated: 2026-09-03T15:13:54.624Z
Reserved: 2026-08-17T15:22:54.443Z
Link: CVE-2026-75033
Updated: 2026-09-03T15:13:42.638Z
Status : Received
Published: 2026-09-03T15:17:32.873
Modified: 2026-09-03T16:18:22.243
Link: CVE-2026-75033
No data.
OpenCVE Enrichment
No data.