LOW
siderolabs
CVE published 2026-09-17
CVE-2026-45723
An authenticated Operator can submit traversal segments in TalosVersion to managementServer.CreateSchematic in Omni, enabling same-host endpoint probing and possible disclosure of internal diagnostics. This issue arises from the lack of validation in the managementServer.CreateSchematic function, which passes the caller-controlled TalosVersion field to imageFactoryClient.OverlaysVersions. As a result, an [truncated]