Impact
When a standalone Talos cluster is imported into Omni, an ImportedClusterSecrets resource is created that contains the full CA secrets bundle for Kubernetes, Talos, etcd, and the service‑account key. The access controls for the ResourceService allow any authenticated user endowed with the Reader role to fetch this resource if the importing actor has not rotated the secrets. An attacker who obtains these private keys can sign certificates, giving them control over privileged identities such as system:masters and enabling full authority over the imported cluster, its workloads, and stored secrets.
Affected Systems
The vulnerability affects the Siderolabs Omni product, specifically versions starting at 1.3.0 and up until the fixes in releases 1.6.6 and 1.7.3. The issue was resolved in releases 1.6.6 and 1.7.3.
Risk and Exploitability
The CVSS score of 7.6 places this issue in the medium‑to‑high severity range, while an EPSS score of less than 1% suggests a low but non‑zero probability of exploitation. The vulnerability is not currently listed in CISA’s KEV catalog. Exploitation requires an authenticated Reader‑level user to access the ResourceService; the attacker also needs to ensure that the importing actor has not already rotated the cluster’s secrets, which typically occurs shortly after import. If these conditions are met, the attacker can acquire full cluster control without further compromise.
OpenCVE Enrichment
Github GHSA