CVE-2026-75033: Rancher: Cross-Cluster Secret Leakage via Namespace projectId Annotation Spoofing

Published Sep 3, 2026
·
Updated

A flaw was found in Rancher Manager. Project Secrets were propagated into a namespace based only on its field.cattle.io/projectId annotation, without verifying that the referenced project belonged to the same downstream cluster. A user able to create namespaces on one cluster could set the annotation to a project ID from another cluster and have that project's secrets copied into a namespace under their control.

This issue affects Rancher: before 2.15.1.

Affected Software

1 affected component
Rancher Rancher Manager<2.15.1

Event History

Sep 3, 2026
CVE Published
via MITRE·02:57 PM
Data Sourced
via MITRE·02:57 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

A user who can create namespaces on one downstream cluster can exploit it by setting a namespace's field.cattle.io/projectId annotation to a project ID associated with another downstream cluster.

2

What information could be exposed?

Project Secrets from the referenced project can be copied into a namespace controlled by the attacker. The impact is cross-cluster secret disclosure.

3

Are affected systems limited to a particular configuration?

The issue affects Rancher Manager versions before 2.15.1 where Project Secrets are propagated based only on the namespace field.cattle.io/projectId annotation. Exploitation requires namespace-creation capability on a downstream cluster.

4

How can I determine whether suspicious exploitation may have occurred?

Review namespaces for field.cattle.io/projectId annotations that reference projects belonging to a different downstream cluster, and check whether Project Secrets were copied into those namespaces.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203