Description
Flyte 2.0.1 through 2.0.51 contains a cleartext secret storage vulnerability that allows users with Pod read access to obtain secrets by reading init container environment variables. The embedded secret manager webhook writes base64-encoded FILE-mounted secret values into the SECRETS environment variable, letting principals without Secret store access decode them from the Pod spec.
Published: 2026-10-11
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Secret disclosure
Action: Apply patch
AI Analysis

Impact

Flyte versions 2.0.1 through 2.0.51 contain a cleartext secret storage vulnerability that allows any user with read access to a Pod to obtain secret values. The embedded secret manager webhook writes base64‑encoded, file‑mounted secret values into the SECRETS environment variable of an init container. Attendees can then read the Pod specification, decode the environment variable, and recover the original secret, thereby compromising confidentiality of sensitive data.

Affected Systems

The affected product is Flyte, developed by flyteorg. All releases from 2.0.1 up to and including 2.0.51 are vulnerable. Users of these versions should verify their current deployment version and apply an upgrade if they are running an affected release.

Risk and Exploitability

The vulnerability has a CVSS score of 7.1, indicating a high severity. No EPSS score is available, and the issue is not listed in the CISA KEV catalog. Exploitation requires that an attacker or user possesses Pod read permissions, a privilege that may be granted in many Multi‑Tenant or RBAC‑managed Kubernetes environments. Once an attacker can read the Pod description, they can immediately decode the SECRETS environment variable and expose all stored secrets. The attack vector is therefore largely dependent on the attacker’s level of internal access and the configuration of RBAC policies.

Generated by OpenCVE AI on October 11, 2026 at 13:44 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Flyte to 2.0.52 or a later release that removes the cleartext exposure of secrets via the admission webhook.
  • Restrict Pod read permissions to trusted administrators only; remove read access from users or groups that do not need it.
  • Reconfigure tasks to store secrets in a secure secret management system rather than embedding them in the init container environment variable.

Generated by OpenCVE AI on October 11, 2026 at 13:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 12:45:00 +0000

Type Values Removed Values Added
Description Flyte 2.0.1 through 2.0.51 contains a cleartext secret storage vulnerability that allows users with Pod read access to obtain secrets by reading init container environment variables. The embedded secret manager webhook writes base64-encoded FILE-mounted secret values into the SECRETS environment variable, letting principals without Secret store access decode them from the Pod spec.
Title Flyte 2.0.1 through 2.0.51 Cleartext Secret Exposure via Admission Webhook
Weaknesses CWE-312
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-11T12:19:36.569Z

Reserved: 2026-10-11T01:52:34.655Z

Link: CVE-2026-108728

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-11T13:17:16.590

Modified: 2026-10-11T13:17:16.590

Link: CVE-2026-108728

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T13:45:03Z

Weaknesses
  • CWE-312

    Cleartext Storage of Sensitive Information