sealed-secrets /v1/rotate can widen sealing scope to cluster-wide via attacker-controlled template annotations
Fixed in: sealed-secrets v0.36.0
details
- Finding IDs
- F-SEALED-SECRETS-ROTATE-SCOPE-001
- CVE
- CVE-2026-22728
- GHSA
- GHSA-465p-v42x-3fmj
- Status
- patched
- Fixed in
- sealed-secrets v0.36.0
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
- CVE registry state
- PUBLISHED
- CVE state checked
- Upstream title
- sealed-secrets /v1/rotate can widen sealing scope to cluster-wide via attacker-controlled template annotations
- Upstream CWE
- CWE-284
- Upstream publication
- Upstream updated
- Metadata fetched
- Upstream @1seal credit
- @1seal: reporter (accepted)
F-SEALED-SECRETS-ROTATE-SCOPE-001: Access control. Rotation can widen a namespace-scoped secret to cluster scope. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-SEALED-SECRETS-ROTATE-SCOPE-001
Security area (1seal assessment): Authorization. Rotation can widen a sealed secret from its original name/namespace scope to cluster-wide access. Reviewed 21 Sep 2026.