CVE-2026-105165Medium· 6.3▾ SunlitA vulnerability has been found in devopspolis secrets-replicator up to 0.4.0. Impacted is the function process_single_secret of the file src/handler.py of the component AssumeRole Handler. Such manipulation of the argument external_id le…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 34.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A vulnerability has been found in devopspolis secrets-replicator up to 0.4.0. Impacted is the function process_single_secret of the file src/handler.py of the component AssumeRole Handler. Such manipulation of the argument external_id leads to incorrect permission assignment. The attack can be executed remotely. Upgrading to version 0.5.0 is recommended to address this issue. The name of the patch is b42239405fbf4fae3c3f0048fc0b4225112edceb. It is suggested to upgrade the affected component.
secrets-replicator 0.1secrets-replicator 0.2secrets-replicator 0.3secrets-replicator 0.4.0Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-10840High· 7.1A flaw was found in the OpenShift Pipelines operator
CVE-2026-0775High· 7.0npm cli Incorrect Permission Assignment Local Privilege Escalation Vulnerability
CVE-2026-104854High· 8.5Nx is a monorepo solution for TypeScript and polyglot codebases
CVE-2026-22676High· 7.8Barracuda RMM < 2025.2.2 Privilege Escalation via Insecure Directory Permissions
CVE-2025-34135Medium· 4.4Nagios XI versions prior to 2024R1.4.2 configure some systemd unit files with permission sets that were too permissive
CVE-2026-47518Medium· 6.0NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in a secure microcontroller component, where incorrect permission assignment for a critical resource allows an attacker with privileged local access to modify prote…