以下是该漏洞描述的中文翻译: Rancher Manager 中存在一个缺陷:项目密钥(Project Secrets)仅根据命名空间的 注解进行传播,而未验证所引用的项目是否属于同一个下游集群。因此,一个能够创建命名空间的用户可以将注解设置为来自另一个集群的项目 ID,从而将该项目下的密钥复制到该用户所控制的命名空间中。 此问题影响 Rancher 2.15.1 之前的版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-71404 | 8.7 HIGH | Rancher: Ownership-less ClusterRole overwrite via attacker-controlled cr-name annotation o |
| CVE-2026-75035 | 7.7 HIGH | Rancher: ext.cattle.io/v1 Token store: cross-user token disclosure via label-selector scop |
| CVE-2026-75034 | 7.4 HIGH | Rancher: SAML Assertion Replay |
| CVE-2026-71403 | 6.1 MEDIUM | Rancher: Identity-field mutation in /v3/users allows account hijack via principal rebind |
| CVE-2026-75036 | 5.3 MEDIUM | Fleet: DNS exfiltration via Sprig getHostByName in fleet.yaml Helm template preprocessing |
No comments yet