Kubernetes Vulnerability in Omni Affecting Talos Clusters
CVE-2026-45726
7.6HIGH
What is CVE-2026-45726?
The vulnerability in Omni affects versions up to 1.6.6 and 1.7.3, where an ImportedClusterSecrets resource exposes the complete CA secrets bundle of a Talos cluster. Authenticated users with the Reader role may access these secrets if the original importing actor has not rotated them. This exposure allows unauthorized retrieval of Kubernetes CA private keys and service-account keys, potentially granting control over the cluster's workloads, secrets, and credentials beyond Omni's intended authorization boundaries. Versions 1.6.6 and 1.7.3 address this issue with enhanced security measures.
Affected Version(s)
omni >= 1.3.0, < 1.6.6
