Rancher Backup Operator S3 Token Leakage Vulnerability

Vulnerability

A vulnerability in the Rancher Backup Operator has been identified, allowing S3 tokens (accessKey and secretKey) to be leaked into the logs of the rancher-backup-operator pod. This issue affects versions 6.0.0 prior to 6.0.3, 7.0.0 prior to 7.0.5, 8.0.0 prior to 8.1.2, and 9.0.0 prior to 9.0.1. The leakage occurs under specific logging level conditions, with the accessKey exposed by default and the secretKey requiring a modification of the logging levels.

Impact

The vulnerability leads to the unintentional exposure of sensitive S3 credentials in pod logs, which could be exploited to gain unauthorized access to S3 resources.

Remediation

Users should upgrade to Rancher Backup Operator versions 9.0.1, 8.1.2, 7.0.5, or 6.0.3. After upgrading, it is recommended to rotate the S3 accessKey and secretKey, especially if logs were exported. For air-gapped Rancher clusters, the Rancher version must be updated first before accessing the patched version of the Rancher Backup chart. Users who cannot update either Rancher or Rancher Backup should ensure that the debug and trace logging levels are set to false, the default, to prevent potential leaks.

Added: Mar 4, 2026, 4:20 PM
Updated: Mar 4, 2026, 6:26 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
4.8
remediation
0.0
relevance
3.5
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.