Junglewise Threat Intelligence

CVE-2026-75035: Rancher Manager access control bypass in Token API

CVE-2026-75035 · Severity: high · CVSS 7.7 · Published 2026-09-03

Technologies: Suse Rancher, Suse Rancher Manager. Vendors: Suse.

Executive brief

Rancher Manager is a platform for managing Kubernetes clusters across an organization. A flaw in its token management system allowed any authenticated user to view other users' API tokens, including the cryptographic hash of the bearer token itself. An attacker with any valid credentials could exploit this to steal or impersonate other users' service accounts, potentially gaining unauthorized access to cluster resources.

Technical details

The vulnerability is an access control bypass in the ext.cattle.io/v1 Token API store. When a non-administrative user supplied a label selector targeting a different user, the internal owner filter was incorrectly dropped instead of returning an empty result, allowing the listing and watching of all tokens across all users. The flaw affects the imperative Token API and allows authenticated attackers to disclose token metadata and the stored salted hash of bearer tokens. The fix enforces per-user scoping unconditionally at the store level and removes the token hash from read responses. The vulnerability was patched in Rancher v2.15.1.

Affected products

  • SUSE Rancher Manager before 2.15.1

Timeline

  • 2026-09-03: disclosed
  • 2026-08-28: patched: Fix included in v2.15.1 release

References

Related threats