{"id":"CVE-2026-59341","title":"A security vulnerability exists in the Sealed Secrets controller's unauthenticated POST endpoints","summary":"A security vulnerability exists in the Sealed Secrets controller's unauthenticated POST endpoints. By submitting a modified payload containing custom Go template logic in spec.template.data, an attacker with internal network access can a…","severity":"medium","cvss":4.2,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N","cwe":["CWE-203"],"vendor":"Bitnami","product":"sealed-secrets","affected":["sealed-secrets <= 0.38.4"],"published":"2026-09-15","updated":"2026-09-18","sourceUpdated":"2026-09-18T19:21:34.307","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-59341","references":[{"url":"https://github.com/bitnami/sealed-secrets","label":"security@vmware.com"},{"url":"https://github.com/bitnami/sealed-secrets/security/advisories/GHSA-qj4p-m373-p2wg","label":"security@vmware.com"},{"url":"https://github.com/bitnami/sealed-secrets/security/advisories/GHSA-qj4p-m373-p2wg","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","cve.org","exploit-available"],"epss":0.00313,"epssPercentile":0.24362,"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-15T17:27:25.731287Z"},"ingestedAt":"2026-09-15T09:34:49.387Z","slug":"CVE-2026-59341","body":"## Overview\n\nA security vulnerability exists in the Sealed Secrets controller's unauthenticated POST endpoints. By submitting a modified payload containing custom Go template logic in spec.template.data, an attacker with internal network access can abuse the handler as a decryption oracle to recover the full plaintext of any sealed secret.\n\n\n\nThe POST /v1/verify and /v1/rotate handlers call Unseal() to decrypt target secrets, then render any Go templates found in spec.template.data.* using the decrypted payload as the evaluation context (pkg/apis/sealedsecrets/v1alpha1/sealedsecret_expansion.go). Errors encountered during template execution are directly reflected in the resulting HTTP response status codes.\n\n\n\nMissing AEAD label binding: the spec.template.data field is omitted from the AEAD authenticated-data label binding ciphertext to metadata. As a result, an attacker can copy a target's valid metadata and encryptedData verbatim, satisfying AEAD decryption and label validation, while freely replacing spec.template.data with arbitrary template logic.\n\n\n\nSide-channel oracle: template execution errors map directly to HTTP response codes. HTTP 200 (OK) indicates template execution succeeded; HTTP 409 (Conflict) indicates template execution failed (e.g. via {{ fail \"...\" }}).\n\n\n\nBy injecting conditional statements such as {{ if eq (substr 0 1 .password) \"S\" }}ok{{ else }}{{ fail \"x\" }}{{ end }}, an attacker receives an HTTP 200 status when a character guess is correct and an HTTP 409 when it is incorrect. This differential response leaks one character-equality bit per request, allowing full secret extraction over successive queries.\n\n\n\nAttack vector & prerequisites: unauthenticated; requires network access to the controller's internal service port (:8080). Although this service is not exposed to the public internet by default, it is accessible to any pod within the Kubernetes cluster or via a kubectl port-forward connection.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":35,"depthScoreParts":{"impact":23.1,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[{"seq":204341,"id":"CVE-2026-59341","ts":1789494100050,"field":"exploit_available","old":"false","new":"true"}]}