Description
Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.6.6 and 1.7.3, managementServer.CreateSchematic in internal/backend/grpc/schematics.go passes the caller-controlled TalosVersion field to imageFactoryClient.OverlaysVersions without validating it as a version. An authenticated Operator can submit traversal segments in TalosVersion, and url.URL.JoinPath normalizes them into unintended paths on the configured image-factory host. Omni then issues HTTP GET requests to those paths and reflects error-body content, enabling same-host endpoint probing and possible disclosure of internal diagnostics while preventing redirection to another host or write requests. This issue is fixed in versions 1.6.6 and 1.7.3.
Published: 2026-09-17
Score: 2.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure via Path Traversal
Action: Apply Patch
AI Analysis

Impact

A caller-controlled TalosVersion value is passed to an image‑factory client without validation. The value may contain path‑traversal segments that the URL joining logic normalizes into unintended paths on the image‑factory host. When the backend makes HTTP GET requests to those paths, the error bodies are reflected back to the operator, allowing probing of same‑host endpoints and possible disclosure of internal diagnostics. The flaw does not allow redirection to other hosts or write operations.

Affected Systems

The affected product is Omni by siderolabs. Versions prior to 1.6.6 and 1.7.3 are vulnerable. The vulnerability is relevant for deployments that use the managementServer.CreateSchematic gRPC endpoint to create schematics on Kubernetes clusters.

Risk and Exploitability

The CVSS score of 2.7 indicates low overall impact, and the EPSS score is listed as below 1 %, reflecting a very low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. An authenticated Operator who can invoke CreateSchematic represents the attack scenario. The path traversal can only probe endpoints on the configured image‑factory host and does not achieve remote code execution or cross‑domain access, but it can reveal internal diagnostic information that may aid further attacks.

Generated by OpenCVE AI on September 19, 2026 at 02:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Omni to version 1.6.6 or later, or to version 1.7.3 or later, which contains the fix for the unchecked TalosVersion parameter
  • Ensure that the image‑factory host configuration does not expose diagnostic endpoints to unrestricted operators
  • After applying the patch, verify that any previously exposed error‑body content is no longer reflected in responses to operator requests

Generated by OpenCVE AI on September 19, 2026 at 02:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-c66c-vq6w-fvh5 Omni: Operator can traverse image-factory API paths via unsanitized `talos_version` in CreateSchematic
History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Siderolabs
Siderolabs omni
Vendors & Products Siderolabs
Siderolabs omni

Thu, 17 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.6.6 and 1.7.3, managementServer.CreateSchematic in internal/backend/grpc/schematics.go passes the caller-controlled TalosVersion field to imageFactoryClient.OverlaysVersions without validating it as a version. An authenticated Operator can submit traversal segments in TalosVersion, and url.URL.JoinPath normalizes them into unintended paths on the configured image-factory host. Omni then issues HTTP GET requests to those paths and reflects error-body content, enabling same-host endpoint probing and possible disclosure of internal diagnostics while preventing redirection to another host or write requests. This issue is fixed in versions 1.6.6 and 1.7.3.
Title Omni: Operator can traverse image-factory API paths via unsanitized `talos_version` in CreateSchematic
Weaknesses CWE-20
CWE-209
CWE-22
CWE-441
CWE-918
References
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-18T20:13:13.232Z

Reserved: 2026-05-13T05:51:48.666Z

Link: CVE-2026-45723

cve-icon Vulnrichment

Updated: 2026-09-18T20:13:09.465Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-17T20:16:49.347

Modified: 2026-09-23T18:12:04.247

Link: CVE-2026-45723

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T02:30:17Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-209

    Generation of Error Message Containing Sensitive Information

  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

  • CWE-441

    Unintended Proxy or Intermediary ('Confused Deputy')

  • CWE-918

    Server-Side Request Forgery (SSRF)