Description
Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. From 1.3.0 until 1.6.6 and 1.7.3, importing a standalone Talos cluster creates an ImportedClusterSecrets resource containing the cluster's complete CA secrets bundle. The access rules in internal/backend/runtime/omni/state_access.go allow an authenticated user with the Reader role to retrieve the resource through ResourceService if the importing actor has not rotated those secrets, exposing Kubernetes, Talos, and etcd CA private keys plus the service-account key. The Kubernetes CA private key permits certificate signing for privileged identities such as system:masters and provides control of the imported cluster outside Omni's authorization boundary, including its workloads, credentials, and secrets. This issue is fixed in versions 1.6.6 and 1.7.3.
Published: 2026-09-17
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation via Cluster Secrets Disclosure
Action: Patch
AI Analysis

Impact

When a standalone Talos cluster is imported into Omni, an ImportedClusterSecrets resource is created that contains the full CA secrets bundle for Kubernetes, Talos, etcd, and the service‑account key. The access controls for the ResourceService allow any authenticated user endowed with the Reader role to fetch this resource if the importing actor has not rotated the secrets. An attacker who obtains these private keys can sign certificates, giving them control over privileged identities such as system:masters and enabling full authority over the imported cluster, its workloads, and stored secrets.

Affected Systems

The vulnerability affects the Siderolabs Omni product, specifically versions starting at 1.3.0 and up until the fixes in releases 1.6.6 and 1.7.3. The issue was resolved in releases 1.6.6 and 1.7.3.

Risk and Exploitability

The CVSS score of 7.6 places this issue in the medium‑to‑high severity range, while an EPSS score of less than 1% suggests a low but non‑zero probability of exploitation. The vulnerability is not currently listed in CISA’s KEV catalog. Exploitation requires an authenticated Reader‑level user to access the ResourceService; the attacker also needs to ensure that the importing actor has not already rotated the cluster’s secrets, which typically occurs shortly after import. If these conditions are met, the attacker can acquire full cluster control without further compromise.

Generated by OpenCVE AI on September 19, 2026 at 03:01 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Omni to version 1.6.6 or 1.7.3, or later, to apply the security fix.
  • If an immediate upgrade is not feasible, rotate the imported cluster’s CA secrets to invalidate the exposed bundle.
  • Review and restrict the use of the Reader role, limiting it only to users who truly need cluster read access, and consider revoking the role from unnecessary users.

Generated by OpenCVE AI on September 19, 2026 at 03:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-wv8c-6mx2-xf4j Omni: Reader-level users can retrieve imported cluster CA keys via ResourceService
History

Mon, 21 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Siderolabs
Siderolabs omni
Vendors & Products Siderolabs
Siderolabs omni

Thu, 17 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. From 1.3.0 until 1.6.6 and 1.7.3, importing a standalone Talos cluster creates an ImportedClusterSecrets resource containing the cluster's complete CA secrets bundle. The access rules in internal/backend/runtime/omni/state_access.go allow an authenticated user with the Reader role to retrieve the resource through ResourceService if the importing actor has not rotated those secrets, exposing Kubernetes, Talos, and etcd CA private keys plus the service-account key. The Kubernetes CA private key permits certificate signing for privileged identities such as system:masters and provides control of the imported cluster outside Omni's authorization boundary, including its workloads, credentials, and secrets. This issue is fixed in versions 1.6.6 and 1.7.3.
Title Omni: Reader-level users can retrieve imported cluster CA keys via ResourceService
Weaknesses CWE-200
CWE-522
CWE-732
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-21T21:09:15.556Z

Reserved: 2026-05-13T05:51:48.667Z

Link: CVE-2026-45726

cve-icon Vulnrichment

Updated: 2026-09-21T21:09:10.167Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T20:16:49.650

Modified: 2026-09-24T21:25:27.050

Link: CVE-2026-45726

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T03:15:16Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-522

    Insufficiently Protected Credentials

  • CWE-732

    Incorrect Permission Assignment for Critical Resource