---
id: CVE-2026-75035
title: A flaw was found in Rancher Manager
summary: >-
  A flaw was found in Rancher Manager. When a non-administrative caller supplied
  a label selector naming a different user, the ext.cattle.io/v1 Token store
  dropped its internal owner filter instead of returning an empty result. Any
  authent…
severity: high
cvss: 7.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'
cwe:
  - CWE-639
vendor: suse
product: rancher
affected:
  - rancher < 2.15.1
patched:
  - rancher 2.15.1
published: '2026-09-03'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T14:26:46.927'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-75035'
references:
  - url: 'https://github.com/rancher/rancher/releases/tag/v2.15.1'
    label: meissner@suse.de
tags:
  - nvd
epss: 0.0034
epssPercentile: 0.24816
ingestedAt: '2026-09-05T20:44:36.671Z'
---

## Overview

A flaw was found in Rancher Manager. When a non-administrative caller supplied a label selector naming a different user, the ext.cattle.io/v1 Token store dropped its internal owner filter instead of returning an empty result. Any authenticated user could therefore list and watch every other user's tokens, disclosing token metadata and the stored salted hash of the bearer token.



This issue affects Rancher: before 2.15.1.

## Affected

- `rancher < 2.15.1`

## Remediation

Upgrade past the affected range:

- `rancher 2.15.1`
