Vulnerability Description
Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. From 1.3.0 until 1.6.6 and 1.7.3, importing a standalone Talos cluster creates an ImportedClusterSecrets resource containing the cluster's complete CA secrets bundle. The access rules in internal/backend/runtime/omni/state_access.go allow an authenticated user with the Reader role to retrieve the resource through ResourceService if the importing actor has not rotated those secrets, exposing Kubernetes, Talos, and etcd CA private keys plus the service-account key. The Kubernetes CA private key permits certificate signing for privileged identities such as system:masters and provides control of the imported cluster outside Omni's authorization boundary, including its workloads, credentials, and secrets. This issue is fixed in versions 1.6.6 and 1.7.3.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/siderolabs/omni/commit/25fa9e141ee00285e70210ed40d11e4e457c87
- https://github.com/siderolabs/omni/commit/a224cb020f3aaca2bc21c3e32a38eb4a37e531
- https://github.com/siderolabs/omni/commit/b8ca100c4539ea83f0ac2e53dcd523e6e5b681
- https://github.com/siderolabs/omni/pull/2807
- https://github.com/siderolabs/omni/releases/tag/v1.6.6
- https://github.com/siderolabs/omni/releases/tag/v1.7.3
- https://github.com/siderolabs/omni/security/advisories/GHSA-wv8c-6mx2-xf4j
FAQ
What is CVE-2026-45726?
CVE-2026-45726 is a vulnerability with a CVSS score of 7.6 (HIGH). Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. From 1.3.0 until 1.6.6 and 1.7.3, importing a standalone Talos cluster creates an ImportedClusterSecrets resource containing the...
How severe is CVE-2026-45726?
CVE-2026-45726 has been rated HIGH with a CVSS base score of 7.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-45726?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.