Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-45720— Omni: TOCTOU race condition allows multiple concurrent uses of a single-use SAML session token

Quick assessment

Affected
siderolabs omni
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Omni 支持在裸金属、虚拟机或云端环境中管理 Kubernetes。在 1.6.6 之前,以及 1.7.0 至 1.7.3 版本中,位于 中的 函数在检查 状态时,将“检查”和“标记为已使用”分为两个独立的状态操作。当多个并发请求携带相同的已捕获 SAML 会话令牌时,每个请求都可能观察到该断言尚未被使用,并在此之前完成认证,从而以受害者身份获得认证。攻击者可以调用受 SAML 保护的 gRPC 端点,利用 创建多个与受害者绑定的持久性凭证,并生成归因于受害者的审计记录。根据受害者的权限,由此产生的访问可能影响机

CVSS 7.0 · High EPSS 0.02% · P5

Affected Version Matrix 2

VendorProduct Version RangeStatus
siderolabs omni < 1.6.6 affected
>= 1.7.0, < 1.7.3 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-45720

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Omni: TOCTOU race condition allows multiple concurrent uses of a single-use SAML session token
Source: CVE Program / CVE List V5
Vulnerability Description
Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.6.6 and from 1.7.0 until 1.7.3, SAML.getSession in internal/pkg/auth/interceptor/saml.go checks SAMLAssertion.Used and marks it used in separate state operations. Concurrent requests carrying the same captured saml-session token can each observe the assertion as unused and obtain authentication as the victim before either update is visible. The attacker can invoke SAML-protected gRPC endpoints, use ConfirmPublicKey to create multiple persistent credentials tied to the victim, and generate audit entries attributed to the victim, with the resulting access potentially affecting confidentiality, integrity, and availability according to the victim's privileges. This issue is fixed in versions 1.6.6 and 1.7.3.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
使用捕获-重放进行的认证绕过
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
siderolabs omni < 1.6.6 -

II. Public POCs for CVE-2026-45720

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-45720

登录查看更多情报信息。

Patches & Fixes for CVE-2026-45720 (4)

Vendor Advisories for CVE-2026-45720 (1)

Vendor Pages for CVE-2026-45720 (2)

Same Patch Batch · siderolabs · 2026-09-17 · 3 CVEs total

CVE-2026-45726 7.6 HIGH Omni: Reader-level users can retrieve imported cluster CA keys via ResourceService
CVE-2026-45723 2.7 LOW Omni: Operator can traverse image-factory API paths via unsanitized `talos_version` in Cre

IV. Related Vulnerabilities

V. Comments for CVE-2026-45720

No comments yet


Leave a comment