PatchSiren cyber security CVE debrief
CVE-2026-75035 SUSE CVE debrief
CVE-2026-75035 debrief based on CVE Program and NVD records. This vulnerability affects Rancher Manager, allowing authenticated users to disclose token metadata and stored salted hashes of bearer tokens. The issue arises when a non-administrative caller supplies a label selector naming a different user, causing the ext.cattle.io/v1 Token store to drop its internal owner filter. Rancher users, administrators, and security teams should assess exposure and prioritize patching to version 2.15.1 or later.
- Vendor
- SUSE
- Product
- Rancher
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-03
- Original CVE updated
- 2026-09-05
- Advisory published
- 2026-09-03
- Advisory updated
- 2026-09-05
Who should care
Rancher users, administrators, and security teams should assess exposure and prioritize patching. This includes reviewing and monitoring token usage and permissions, as well as verifying Rancher version and exposure. Security teams should also review compensating controls for exposed systems while remediation is scheduled and verified. Additionally, checking relevant monitoring, detection, and logs for exposed assets that need extra review is crucial. Tracking exceptions, retesting remediated assets, and closing the item only after evidence is documented are also important steps. The vulnerability's impact on operator, platform, vulnerability-management, and security-team operations necessitates prompt attention and action to prevent potential unauthorized access to sensitive information and ensure the security of Rancher Manager deployments. This requires coordination between Rancher users, administrators, and security teams to ensure comprehensive mitigation and minimize potential operational impacts. Therefore, it is essential for these stakeholders to work together to verify and patch affected systems, review and monitor token usage, and implement compensating controls as needed to prevent exploitation. By taking these steps, organizations can reduce the risk associated with CVE-2026-75035 and protect their Rancher Manager deployments from potential attacks. Effective communication and collaboration between stakeholders are critical to successfully mitigating this vulnerability and maintaining the security and integrity of Rancher Manager environments. The CVE Program and NVD records provide details on the vulnerability, and their guidance should be consulted to ensure comprehensive mitigation and minimize potential operational impacts. Rancher users and administrators must prioritize verification and patching to prevent potential security breaches and ensure the integrity of their Rancher Manager deployments. Security teams must also be proactive in monitoring and detecting potential security incidents related to this vulnerability, and take prompt action to mitigate any identified risks. By working together and taking a proactive approach to security, Ranr
Why it matters
CVE-2026-75035 allows authenticated users to disclose token metadata and stored salted hashes in Rancher Manager, requiring verification and patching by Rancher users.
- Authenticated users can disclose token metadata and stored salted hashes of bearer tokens
- Potential for unauthorized access to sensitive information
- Need for verification of Rancher version and exposure
- Priority for patching to version 2.15.1 or later
Technical summary
A flaw in Rancher Manager allows authenticated users to list and watch every other user's tokens, disclosing token metadata and stored salted hashes, due to a dropped internal owner filter when a non-administrative caller supplies a label selector naming a different user. This issue affects Rancher versions before 2.15.1. The vulnerability can be mitigated by verifying Rancher version and assessing exposure, then patching to version 2.15.1 or later.
Defensive priority
Rancher users should prioritize verification and patching
Recommended defensive actions
- Verify Rancher version and assess exposure
- Patch Rancher to version 2.15.1 or later
- Review and monitor token usage and permissions
- Verify token usage and permissions
- Monitor for suspicious activity
- Implement additional compensating controls
- Review and update incident response plans
Evidence notes
The CVE Program and NVD records provide details on the vulnerability in Rancher Manager, allowing authenticated users to list and watch every other user's tokens, disclosing token metadata and stored salted hashes.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-75035 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-75035
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-75035 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-75035
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/rancher/rancher/releases/tag/v2.15.1
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.