PT-2026-46989 · Omni · Omni

CVE-2026-45726

·

Published

2026-06-05

·

Updated

2026-07-30

CVSS v3.1

7.6

High

VectorAV:A/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Omni (affected versions not specified)
Description An authenticated user with Reader access can retrieve the ImportedClusterSecrets resource during the process of importing standalone Talos clusters. This resource contains the full CA secrets bundle, including the Kubernetes CA, etcd CA, and service account keys. An attacker with these private keys can sign certificates for any Kubernetes user or group, such as system:masters, granting full cluster-admin access to the imported cluster's Kubernetes, Talos, and etcd APIs independently of the Omni control plane. This allows for complete control over Kubernetes workloads, credentials, and secrets within the affected imported cluster.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Permission

Insufficiently Protected Credentials

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45726
GHSA-WV8C-6MX2-XF4J
GO-2026-5725
OPENSUSE-SU-2026:21483-1

Affected Products

Omni