Path Traversal Vulnerability in Omni Kubernetes Management by Sidero Labs
CVE-2026-45723

2.7LOW

Key Information:

Vendor

Siderolabs

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-45723?

The Omni management platform for Kubernetes is vulnerable to a path traversal issue that allows an authenticated operator to manipulate the TalosVersion field without proper validation. This flaw could result in the exposure of sensitive information through error responses generated by the configured image-factory host. Attackers could leverage this vulnerability to probe internal endpoints, potentially disclosing diagnostics information while being restricted from redirecting to external hosts or executing write operations. This issue has been addressed in versions 1.6.6 and 1.7.3.

Affected Version(s)

omni < 1.6.6 < 1.6.6

omni >= 1.7.0, < 1.7.3 < 1.7.0, 1.7.3

References

CVSS V3.1

Score:
2.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.