在 Rancher Manager 中发现了一个漏洞。GlobalRole 控制器从用户可设置的 注解中获取目标 ClusterRole 的名称,并在未验证所有权的情况下直接覆盖该对象的权限规则。拥有被委托的 GlobalRole 创建或更新权限的用户可以将该注解指向任意现有的 ClusterRole(例如 ),从而撤销所有绑定到该角色上的主体的权限。即使删除了恶意创建的 GlobalRole,这一权限变更仍然会保留。 该问题影响 Rancher 版本 2.15.1 之前的所有版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-75033 | 7.7 HIGH | Rancher: Cross-Cluster Secret Leakage via Namespace projectId Annotation Spoofing |
| CVE-2026-75035 | 7.7 HIGH | Rancher: ext.cattle.io/v1 Token store: cross-user token disclosure via label-selector scop |
| CVE-2026-75034 | 7.4 HIGH | Rancher: SAML Assertion Replay |
| CVE-2026-71403 | 6.1 MEDIUM | Rancher: Identity-field mutation in /v3/users allows account hijack via principal rebind |
| CVE-2026-75036 | 5.3 MEDIUM | Fleet: DNS exfiltration via Sprig getHostByName in fleet.yaml Helm template preprocessing |
No comments yet