Impact
Omni’s authentication interceptor contains a time‑of‑check to time‑of‑use race condition that permits concurrent requests to reuse a single‑use SAML session token. The flaw allows an attacker who can capture or otherwise obtain a victim’s SAML session token to authenticate repeatedly and create additional persistent credentials tied to that victim. This results in unauthorized access, potential data leakage, integrity violations, and availability impacts consistent with the privileges of the victim account.
Affected Systems
The vulnerability exists in Sidero Labs Omni versions prior to 1.6.6 and from 1.7.0 through 1.7.2. Versions 1.6.6 and 1.7.3 and later contain the fix.
Risk and Exploitability
The CVSS score of 7 indicates high severity, but the EPSS score of less than 1 % suggests exploitation is unlikely at this time. The flaw is not included in CISA’s KEV list. Attack requires the adversary to have network access to Omni’s gRPC endpoints and a valid SAML token, then send simultaneous authentication requests to exploit the race condition.
OpenCVE Enrichment
Github GHSA