SAML Authentication Issue in Omni Kubernetes Management by Sidero Labs
CVE-2026-45720

7HIGH

Key Information:

Vendor

Siderolabs

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-45720?

The Omni platform, developed by Sidero Labs for managing Kubernetes environments, has a vulnerability in its SAML authentication process. This issue relates to the handling of session tokens which can be exploited through concurrent requests. An attacker can potentially utilize a single captured SAML session token to perform unauthorized actions as the victim, accessing SAML-protected gRPC endpoints and generating misleading audit records. This situation raises serious concerns regarding the confidentiality, integrity, and availability of the systems, particularly affecting user privileges. The flaw has been resolved in versions 1.6.6 and 1.7.3.

Affected Version(s)

omni < 1.6.6 < 1.6.6

omni >= 1.7.0, < 1.7.3 < 1.7.0, 1.7.3

References

CVSS V3.1

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.