PT-2026-91906 · Unknown · Sealed-Secrets
CVE-2026-59341
·
Published
2026-09-15
·
Updated
2026-09-16
CVSS v3.1
4.2
Medium
| Vector | AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Sealed Secrets (affected versions not specified)
Description
Unauthenticated POST endpoints in the Sealed Secrets controller allow an attacker with internal network access to use the handler as a decryption oracle to recover the plaintext of any sealed secret. The endpoints '/v1/verify' and '/v1/rotate' utilize the
Unseal() function to decrypt secrets and then render Go templates found in spec.template.data using the decrypted payload as the context. Because the spec.template.data field is omitted from the AEAD (Authenticated Encryption with Associated Data) label binding, an attacker can replace this field with arbitrary template logic while maintaining valid metadata and encrypted data.A side-channel oracle is created because template execution errors map directly to HTTP response codes: HTTP 200 indicates success, while HTTP 409 indicates failure. By injecting conditional statements into the
spec.template.data variable, an attacker can leak character-equality bits through differential responses, enabling full secret extraction. This issue requires network access to the controller's internal service port (:8080), which is accessible to pods within the Kubernetes cluster or via kubectl port-forward.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Side Channel Attack
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sealed-Secrets