PT-2026-91906 · Unknown · Sealed-Secrets

CVE-2026-59341

·

Published

2026-09-15

·

Updated

2026-09-16

CVSS v3.1

4.2

Medium

VectorAV:N/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Sealed Secrets (affected versions not specified)
Description Unauthenticated POST endpoints in the Sealed Secrets controller allow an attacker with internal network access to use the handler as a decryption oracle to recover the plaintext of any sealed secret. The endpoints '/v1/verify' and '/v1/rotate' utilize the Unseal() function to decrypt secrets and then render Go templates found in spec.template.data using the decrypted payload as the context. Because the spec.template.data field is omitted from the AEAD (Authenticated Encryption with Associated Data) label binding, an attacker can replace this field with arbitrary template logic while maintaining valid metadata and encrypted data.
A side-channel oracle is created because template execution errors map directly to HTTP response codes: HTTP 200 indicates success, while HTTP 409 indicates failure. By injecting conditional statements into the spec.template.data variable, an attacker can leak character-equality bits through differential responses, enabling full secret extraction. This issue requires network access to the controller's internal service port (:8080), which is accessible to pods within the Kubernetes cluster or via kubectl port-forward.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Side Channel Attack

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-59341
GHSA-QJ4P-M373-P2WG

Affected Products

Sealed-Secrets