PT-2026-46989 · Omni · Omni
CVE-2026-45726
·
Published
2026-06-05
·
Updated
2026-07-30
CVSS v3.1
7.6
High
| Vector | AV:A/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Omni (affected versions not specified)
Description
An authenticated user with Reader access can retrieve the
ImportedClusterSecrets resource during the process of importing standalone Talos clusters. This resource contains the full CA secrets bundle, including the Kubernetes CA, etcd CA, and service account keys. An attacker with these private keys can sign certificates for any Kubernetes user or group, such as system:masters, granting full cluster-admin access to the imported cluster's Kubernetes, Talos, and etcd APIs independently of the Omni control plane. This allows for complete control over Kubernetes workloads, credentials, and secrets within the affected imported cluster.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Incorrect Permission
Insufficiently Protected Credentials
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Omni