CVE-2026-22728
Gravedad CVSS v3.1:
MEDIA
Tipo:
CWE-284
Control de acceso incorrecto
Fecha de publicación:
26/02/2026
Última modificación:
27/02/2026
Descripción
*** Pendiente de traducción *** Bitnami Sealed Secrets is vulnerable to a scope-widening attack during<br />
the secret rotation (/v1/rotate) flow. The rotation handler derives the<br />
sealing scope for the newly encrypted output from untrusted<br />
spec.template.metadata.annotations present in the input SealedSecret.<br />
By submitting a victim SealedSecret to the rotate endpoint with the<br />
annotation sealedsecrets.bitnami.com/cluster-wide=true injected into the<br />
template metadata, a remote attacker can obtain a rotated version of the<br />
secret that is cluster-wide. This bypasses original "strict" or<br />
"namespace-wide" constraints, allowing the attacker to retarget and unseal<br />
the secret in any namespace or under any name to recover the plaintext<br />
credentials.
Impacto
Puntuación base 3.x
4.90
Gravedad 3.x
MEDIA



