HIGHVulnerability

CVE-2026-75033

A flaw was found in Rancher Manager. Project Secrets were propagated into a namespace based only on its `field.cattle.io/projectId` annotation, without verifying that the referenced project belonged to the same downstream cluster. A user able to create namespaces on one cluster could set the annotation to a project ID from another cluster and have that project's secrets copied into a namespace under their control. This issue affects Rancher: before 2.15.1.

Properties

severity
HIGH
score
7.7
cve_id
CVE-2026-75033
signal_observed_at
2026-09-18T17:46:00+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
published_at
2026-09-03T15:17:32.873
last_modified
2026-09-18T14:56:19.560

Related Entities (3)

HAS_WEAKNESS (1)

[Weakness]Authorization Bypass Through User-Controlled Key

DESCRIBED_BY (1)

[Source]NVD

AFFECTS_PRODUCT (1)

[Product]

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-75033 — Ninja Signal Threat Intelligence | Ninja Signal