Rancher Manager 中发现一个缺陷。此前为修复 CVE-2026-44946 而引入的 SAML 断言重放保护机制,将已使用的断言 ID 记录在每进程(per-process)缓存中,因此每个副本(replica)只能检测到达同一个 Pod 的重放请求。在高可用(HA)部署环境下,持有已捕获断言的攻击者可以将该断言重放一次到每个其他副本,从而为受害者获得额外的已认证会话。 此问题影响 Rancher 2.15.1 之前的版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-71404 | 8.7 HIGH | Rancher: Ownership-less ClusterRole overwrite via attacker-controlled cr-name annotation o |
| CVE-2026-75033 | 7.7 HIGH | Rancher: Cross-Cluster Secret Leakage via Namespace projectId Annotation Spoofing |
| CVE-2026-75035 | 7.7 HIGH | Rancher: ext.cattle.io/v1 Token store: cross-user token disclosure via label-selector scop |
| CVE-2026-71403 | 6.1 MEDIUM | Rancher: Identity-field mutation in /v3/users allows account hijack via principal rebind |
| CVE-2026-75036 | 5.3 MEDIUM | Fleet: DNS exfiltration via Sprig getHostByName in fleet.yaml Helm template preprocessing |
No comments yet