SAML Authentication Issue in Omni Kubernetes Management by Sidero Labs
CVE-2026-45720
7HIGH
What is CVE-2026-45720?
The Omni platform, developed by Sidero Labs for managing Kubernetes environments, has a vulnerability in its SAML authentication process. This issue relates to the handling of session tokens which can be exploited through concurrent requests. An attacker can potentially utilize a single captured SAML session token to perform unauthorized actions as the victim, accessing SAML-protected gRPC endpoints and generating misleading audit records. This situation raises serious concerns regarding the confidentiality, integrity, and availability of the systems, particularly affecting user privileges. The flaw has been resolved in versions 1.6.6 and 1.7.3.
Affected Version(s)
omni < 1.6.6 < 1.6.6
omni >= 1.7.0, < 1.7.3 < 1.7.0, 1.7.3
