---
id: CVE-2026-22728
aliases:
  - GHSA-465p-v42x-3fmj
  - BIT-sealed-secrets-2026-22728
  - GO-2026-4565
title: >-
  Sealed Secrets for Kubernetes: Rotate API Allows Scope Widening from
  Strict/Namespace-Wide to Cluster-Wide via Untrusted Template Annotat…
summary: >-
  Sealed Secrets for Kubernetes: Rotate API Allows Scope Widening from
  Strict/Namespace-Wide to Cluster-Wide via Untrusted Template Annotations
severity: medium
cvss: 4.9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'
vendor: bitnami-labs
product: github.com/bitnami-labs/sealed-secrets
ecosystem: go
affected:
  - github.com/bitnami-labs/sealed-secrets < 0.36.0
patched:
  - github.com/bitnami-labs/sealed-secrets 0.36.0
published: '2026-02-26'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T03:50:34.020538821Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-465p-v42x-3fmj'
references:
  - url: >-
      https://github.com/bitnami-labs/sealed-secrets/security/advisories/GHSA-465p-v42x-3fmj
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-22728'
  - url: >-
      https://github.com/bitnami-labs/sealed-secrets/commit/d57ee4a8357d250e602b995399b525496ab688c1
  - url: 'https://github.com/bitnami-labs/sealed-secrets'
  - url: 'https://github.com/bitnami-labs/sealed-secrets/releases/tag/v0.36.0'
tags:
  - osv
  - go
epss: 0.00352
epssPercentile: 0.26049
ingestedAt: '2026-09-12T03:13:01.751Z'
---

## Overview

This report shows a scope-widening issue in the rotate (re-encrypt) flow: the output scope can be derived from untrusted `spec.template.metadata.annotations` on the input sealed secret.

If a victim sealed secret is strict- or namespace-scoped, an attacker who can submit it to the rotate endpoint can set `sealedsecrets.bitnami.com/cluster-wide=true` in the template metadata and receive a rotated sealed secret that is cluster-wide, enabling retargeting (`metadata.name`/`metadata.namespace`) and unsealing to recover the victim plaintext.

## Relevant Links (Pinned)

- Rotate handler uses `NewSealedSecret(..., secret)` after unsealing: https://github.com/bitnami-labs/sealed-secrets/blob/946bc048f3407117c837da6e4300686522d4c4eb/pkg/controller/controller.go#L560-L606
- Scope derivation reads secret annotations (`SecretScope`): https://github.com/bitnami-labs/sealed-secrets/blob/946bc048f3407117c837da6e4300686522d4c4eb/pkg/apis/sealedsecrets/v1alpha1/sealedsecret_expansion.go#L112-L122

## Root Cause

The rotate flow unseals the input sealed secret to a `Secret`, then reseals using `NewSealedSecret(..., secret)`.

Because `SecretScope(secret)` is computed from secret annotations, and unsealing applies `spec.template` metadata onto the unsealed secret, an attacker can influence the scope of the rotated output by mutating template annotations on the rotate input.

## Attack Path

1. Attacker obtains a victim `SealedSecret` object (for example via read access to resources or logs) and can submit it to the controller rotate endpoint.
2. Attacker sets `spec.template.metadata.annotations.sealedsecrets.bitnami.com/cluster-wide=true` (and optionally retargets name/namespace fields).
3. Rotate returns a resealed, cluster-wide sealed secret that is no longer bound to the victim name/namespace.
4. Attacker unseals the rotated output in their chosen namespace/name to recover the victim plaintext.

## Proof of Concept

Setup + run:

```bash
unzip poc.zip -d poc
cd poc
make test
```

Canonical output (excerpt):

```
[CALLSITE_HIT]: pkg/apis/sealedsecrets/v1alpha1/sealedsecret_expansion.go:112 SecretScope
[PROOF_MARKER]: scope_widened=true rotated_scope=cluster-wide
```

Control output (excerpt):

```
[NC_MARKER]: scope_widened=false strict_scope_preserved=true
```

## Fix Accepted When

Rotate preserves the original sealing scope and does not allow scope widening based on untrusted template metadata; strict or namespace-wide inputs cannot produce cluster-wide outputs.

[poc.zip](https://github.com/user-attachments/files/25080027/poc.zip)
[PR_DESCRIPTION.md](https://github.com/user-attachments/files/25080028/PR_DESCRIPTION.md)
[attack_scenario.md](https://github.com/user-attachments/files/25080029/attack_scenario.md)

## Affected packages

- `github.com/bitnami-labs/sealed-secrets < 0.36.0`

## Remediation

Upgrade to a patched release:

- `github.com/bitnami-labs/sealed-secrets 0.36.0`
