Junglewise Threat Intelligence

CVE-2026-45723: Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.6.6 and 1.7.3, managementServer.CreateSchematic in intern

CVE-2026-45723 · Severity: low · CVSS 3.1 · Published 2026-09-17

Technologies: Sidero Labs Omni, github.com/siderolabs/omni (Go). Vendors: Sidero Labs, Go.

Executive brief

Sidero Labs Omni, a management platform for Talos Linux, contains a vulnerability where an authorized administrator (Operator) can access unintended internal API paths. By manipulating version fields, an attacker can force the system to probe internal network services or leak diagnostic information from the image-factory server. This could lead to the exposure of internal server details or sensitive configuration data.

Technical details

A path traversal vulnerability exists in the `managementServer.CreateSchematic` function within `internal/backend/grpc/schematics.go`. The `TalosVersion` field is passed without sanitization to `imageFactoryClient.OverlaysVersions`, where it is used to construct a URL path. Because `url.URL.JoinPath` resolves `../` sequences, an authenticated Operator can traverse the API path on the configured image-factory server. This allows for Server-Side Request Forgery (SSRF) limited to the image-factory host, where error responses from unintended endpoints are reflected back to the user, potentially leaking internal diagnostics. The issue is fixed in versions 1.6.6 and 1.7.3.

Affected products

  • Sidero Labs Omni < 1.6.6, >= 1.7.0, < 1.7.3

Timeline

  • 2026-06-05: disclosed
  • 2026-06-05: patched
  • 2026-06-05: advisory

References

Related threats