Kubernetes Vulnerability in Omni Affecting Talos Clusters
CVE-2026-45726

7.6HIGH

Key Information:

Vendor

Siderolabs

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-45726?

The vulnerability in Omni affects versions up to 1.6.6 and 1.7.3, where an ImportedClusterSecrets resource exposes the complete CA secrets bundle of a Talos cluster. Authenticated users with the Reader role may access these secrets if the original importing actor has not rotated them. This exposure allows unauthorized retrieval of Kubernetes CA private keys and service-account keys, potentially granting control over the cluster's workloads, secrets, and credentials beyond Omni's intended authorization boundaries. Versions 1.6.6 and 1.7.3 address this issue with enhanced security measures.

Affected Version(s)

omni >= 1.3.0, < 1.6.6

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.