cbcvebase.
CVE-2025-62879
published 2026-03-04

CVE-2025-62879: A vulnerability has been identified within the Rancher Backup Operator, resulting in the leakage of S3 tokens (both accessKey and secretKey) into the…

PriorityP426medium4.9CVSS 3.1
AVNACLPRHUINSUCHINAN
EPSS
0.34%
26.5th percentile
A vulnerability has been identified within the Rancher Backup Operator, resulting in the leakage of S3 tokens (both accessKey and secretKey) into the rancher-backup-operator pod's logs.

Affected

12 ranges
VendorProductVersion rangeFixed in
github.comrancher_backup-restore-operator>= 6.0.0 < 6.0.36.0.3
github.comrancher_backup-restore-operator>= 7.0.0 < 7.0.57.0.5
github.comrancher_backup-restore-operator>= 8.0.0 < 8.1.28.1.2
github.comrancher_backup-restore-operator>= 9.0.0 < 9.0.19.0.1
suserancher>= 6.0.0 < 6.0.36.0.3
suserancher>= 7.0.0 < 7.0.57.0.5
suserancher>= 8.0.0 < 8.1.28.1.2
suserancher>= 9.0.0 < 9.0.19.0.1
suserancher_backup_and_restore_operator>= 6.0.0 < 6.0.36.0.3
suserancher_backup_and_restore_operator>= 7.0.0 < 7.0.57.0.5
suserancher_backup_and_restore_operator>= 8.0.0 < 8.1.28.1.2
suserancher_backup_and_restore_operator>= 9.0.0 < 9.0.19.0.1
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.