Security Vulnerability in devopspolis secrets-replicator Affects Remote Permission Assignments
CVE-2026-105165

5.3MEDIUM

Key Information:

Vendor
CVE Published:
4 October 2026

What is CVE-2026-105165?

A vulnerability exists in devopspolis secrets-replicator affecting versions up to 0.4.0, specifically in the process_single_secret function of the AssumeRole Handler. This flaw allows for exploitation through the manipulation of the external_id argument, leading to improper permissions being assigned. The vulnerability can be exploited remotely, emphasizing the need for immediate action. Users are strongly advised to upgrade to version 0.5.0, which contains the necessary patch (b42239405fbf4fae3c3f0048fc0b4225112edceb) to mitigate this issue.

Affected Version(s)

secrets-replicator 0.1

secrets-replicator 0.2

secrets-replicator 0.3

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

changli (VulDB User)
.