Description
Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.6.6 and from 1.7.0 until 1.7.3, SAML.getSession in internal/pkg/auth/interceptor/saml.go checks SAMLAssertion.Used and marks it used in separate state operations. Concurrent requests carrying the same captured saml-session token can each observe the assertion as unused and obtain authentication as the victim before either update is visible. The attacker can invoke SAML-protected gRPC endpoints, use ConfirmPublicKey to create multiple persistent credentials tied to the victim, and generate audit entries attributed to the victim, with the resulting access potentially affecting confidentiality, integrity, and availability according to the victim's privileges. This issue is fixed in versions 1.6.6 and 1.7.3.
Published: 2026-09-17
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized reuse of SAML session tokens leading to multiple authenticated sessions and potential credential duplication
Action: Immediate Patch
AI Analysis

Impact

Omni’s authentication interceptor contains a time‑of‑check to time‑of‑use race condition that permits concurrent requests to reuse a single‑use SAML session token. The flaw allows an attacker who can capture or otherwise obtain a victim’s SAML session token to authenticate repeatedly and create additional persistent credentials tied to that victim. This results in unauthorized access, potential data leakage, integrity violations, and availability impacts consistent with the privileges of the victim account.

Affected Systems

The vulnerability exists in Sidero Labs Omni versions prior to 1.6.6 and from 1.7.0 through 1.7.2. Versions 1.6.6 and 1.7.3 and later contain the fix.

Risk and Exploitability

The CVSS score of 7 indicates high severity, but the EPSS score of less than 1 % suggests exploitation is unlikely at this time. The flaw is not included in CISA’s KEV list. Attack requires the adversary to have network access to Omni’s gRPC endpoints and a valid SAML token, then send simultaneous authentication requests to exploit the race condition.

Generated by OpenCVE AI on September 19, 2026 at 03:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Omni to version 1.6.6 or newer, or to 1.7.3 or newer; the patch addresses the session‑reuse flaw (CWE‑294) and eliminates the race condition (CWE‑367).
  • If upgrading is unavailable, apply commit 272d3f4d to enforce atomic check‑and‑use logic for SAML assertions, mitigating the CWE‑294 improperly handled session problem and the CWE‑367 race condition.
  • Configure Omni gRPC endpoints to accept connections only from trusted hosts and enable comprehensive logging of authentication requests; monitor for repeated token usage to detect exploitation linked to CWE‑294.

Generated by OpenCVE AI on September 19, 2026 at 03:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-5x9f-6vg5-qg4m Omni has a TOCTOU race condition that allows multiple concurrent uses of a single-use SAML session token
History

Fri, 18 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Siderolabs
Siderolabs omni
Vendors & Products Siderolabs
Siderolabs omni

Thu, 17 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.6.6 and from 1.7.0 until 1.7.3, SAML.getSession in internal/pkg/auth/interceptor/saml.go checks SAMLAssertion.Used and marks it used in separate state operations. Concurrent requests carrying the same captured saml-session token can each observe the assertion as unused and obtain authentication as the victim before either update is visible. The attacker can invoke SAML-protected gRPC endpoints, use ConfirmPublicKey to create multiple persistent credentials tied to the victim, and generate audit entries attributed to the victim, with the resulting access potentially affecting confidentiality, integrity, and availability according to the victim's privileges. This issue is fixed in versions 1.6.6 and 1.7.3.
Title Omni: TOCTOU race condition allows multiple concurrent uses of a single-use SAML session token
Weaknesses CWE-294
CWE-367
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T20:21:50.874Z

Reserved: 2026-05-13T05:51:48.666Z

Link: CVE-2026-45720

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-17T20:16:49.190

Modified: 2026-09-24T21:25:27.050

Link: CVE-2026-45720

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T03:30:18Z

Weaknesses
  • CWE-294

    Authentication Bypass by Capture-replay

  • CWE-367

    Time-of-check Time-of-use (TOCTOU) Race Condition