Description
A security vulnerability exists in the Sealed Secrets controller's unauthenticated POST endpoints. By submitting a modified payload containing custom Go template logic in spec.template.data, an attacker with internal network access can abuse the handler as a decryption oracle to recover the full plaintext of any sealed secret.



The POST /v1/verify and /v1/rotate handlers call Unseal() to decrypt target secrets, then render any Go templates found in spec.template.data.* using the decrypted payload as the evaluation context (pkg/apis/sealedsecrets/v1alpha1/sealedsecret_expansion.go). Errors encountered during template execution are directly reflected in the resulting HTTP response status codes.



Missing AEAD label binding: the spec.template.data field is omitted from the AEAD authenticated-data label binding ciphertext to metadata. As a result, an attacker can copy a target's valid metadata and encryptedData verbatim, satisfying AEAD decryption and label validation, while freely replacing spec.template.data with arbitrary template logic.



Side-channel oracle: template execution errors map directly to HTTP response codes. HTTP 200 (OK) indicates template execution succeeded; HTTP 409 (Conflict) indicates template execution failed (e.g. via {{ fail "..." }}).



By injecting conditional statements such as {{ if eq (substr 0 1 .password) "S" }}ok{{ else }}{{ fail "x" }}{{ end }}, an attacker receives an HTTP 200 status when a character guess is correct and an HTTP 409 when it is incorrect. This differential response leaks one character-equality bit per request, allowing full secret extraction over successive queries.



Attack vector & prerequisites: unauthenticated; requires network access to the controller's internal service port (:8080). Although this service is not exposed to the public internet by default, it is accessible to any pod within the Kubernetes cluster or via a kubectl port-forward connection.
Published: 2026-09-15
Score: 4.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Limited plaintext recovery via decryption oracle
Action: Assess Impact
AI Analysis

Impact

The Sealed Secrets controller exposes an unprotected POST endpoint that decrypts sealed secrets and then processes Go templates embedded in the decrypted payload, a flaw classified as CWE‑203. By submitting a crafted template expression within spec.template.data, an internal attacker can cause the service to return HTTP 200 when a template fragment evaluates successfully and HTTP 409 when it fails. The attacker can exploit this differential response as a decryption oracle to learn one character of the secret and eventually recover the entire plaintext. This vulnerability permits leakage of confidential secret data without authentication but with internal network access, and it does not elevate privileges or allow arbitrary code execution beyond secret disclosure.

Affected Systems

The flaw resides in the Bitnami Sealed Secrets controller, specifically the POST /v1/verify and /v1/rotate handlers. Any pod within the same Kubernetes cluster or an entity connected via kubectl port‑forward can reach the controller’s internal service port 8080. No specific product versions are to the fix later described by Bitnami.

Risk and Exploitability

The CVSS score of 4.2 indicates low overall severity, and the EPSS score is below 1 %, meaning exploitation is not common. The vulnerability is not listed in the CISA KEV catalog. However, because the attack requires only internal network access and exposes the controller service to many pods it is significant. Attackers can recover secrets with limited reconnaissance, making this a concern for environments where secrets are highly sensitive.

Generated by OpenCVE AI on September 20, 2026 at 18:01 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Obtain and apply the latest Bitnami Sealed Secrets release that removes the template processing flaw and binds spec.template.data to the AEAD authenticated data field.
  • Deploy a Kubernetes NetworkPolicy that limits traffic to the controller’s 8080 port so that only trusted control‑plane components can access it; block or sanitize spec.template.data before it reaches the Unseal() function, e.g., reject payloads containing template delimiters or enforce that the field contains only base64‑encoded data.
  • Confirm that the Sealed Secrets controller service is not exposed to external traffic; restrict the service type to ClusterIP and avoid NodePort or LoadBalancer deployments to limit exposure to the internal cluster network.

Generated by OpenCVE AI on September 20, 2026 at 18:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-295
CWE-94

Wed, 16 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-203

Wed, 16 Sep 2026 07:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-295
CWE-94

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Bitnami
Bitnami sealed-secrets
Vendors & Products Bitnami
Bitnami sealed-secrets

Tue, 15 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Description A security vulnerability exists in the Sealed Secrets controller's unauthenticated POST endpoints. By submitting a modified payload containing custom Go template logic in spec.template.data, an attacker with internal network access can abuse the handler as a decryption oracle to recover the full plaintext of any sealed secret. The POST /v1/verify and /v1/rotate handlers call Unseal() to decrypt target secrets, then render any Go templates found in spec.template.data.* using the decrypted payload as the evaluation context (pkg/apis/sealedsecrets/v1alpha1/sealedsecret_expansion.go). Errors encountered during template execution are directly reflected in the resulting HTTP response status codes. Missing AEAD label binding: the spec.template.data field is omitted from the AEAD authenticated-data label binding ciphertext to metadata. As a result, an attacker can copy a target's valid metadata and encryptedData verbatim, satisfying AEAD decryption and label validation, while freely replacing spec.template.data with arbitrary template logic. Side-channel oracle: template execution errors map directly to HTTP response codes. HTTP 200 (OK) indicates template execution succeeded; HTTP 409 (Conflict) indicates template execution failed (e.g. via {{ fail "..." }}). By injecting conditional statements such as {{ if eq (substr 0 1 .password) "S" }}ok{{ else }}{{ fail "x" }}{{ end }}, an attacker receives an HTTP 200 status when a character guess is correct and an HTTP 409 when it is incorrect. This differential response leaks one character-equality bit per request, allowing full secret extraction over successive queries. Attack vector & prerequisites: unauthenticated; requires network access to the controller's internal service port (:8080). Although this service is not exposed to the public internet by default, it is accessible to any pod within the Kubernetes cluster or via a kubectl port-forward connection.
Title Sealed Secrets: decryption oracle via Go template injection in unauthenticated controller endpoints
References
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N'}


Subscriptions

Bitnami Sealed-secrets
cve-icon MITRE

Status: PUBLISHED

Assigner: vmware

Published:

Updated: 2026-09-16T11:53:25.201Z

Reserved: 2026-07-04T18:14:34.672Z

Link: CVE-2026-59341

cve-icon Vulnrichment

Updated: 2026-09-15T17:28:04.448Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T10:17:05.673

Modified: 2026-09-18T19:21:34.307

Link: CVE-2026-59341

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T18:15:17Z

Weaknesses