{"schema_version":"1.7.3","id":"BIT-sealed-secrets-2026-22728","published":"2026-02-26T09:30:00Z","modified":"2026-03-23T04:56:00.640210838Z","aliases":["CVE-2026-22728","GHSA-465p-v42x-3fmj","GO-2026-4565"],"summary":"Bitnami Sealed Secrets /v1/rotate can widen sealing scope to cluster-wide via attacker-controlled template annotations","details":"Bitnami Sealed Secrets is vulnerable to a scope-widening attack during the secret rotation (/v1/rotate) flow. The rotation handler derives the sealing scope for the newly encrypted output from untrusted spec.template.metadata.annotations present in the input SealedSecret. By submitting a victim SealedSecret to the rotate endpoint with the annotation sealedsecrets.bitnami.com/cluster-wide=true injected into the template metadata, a remote attacker can obtain a rotated version of the secret that is cluster-wide. This bypasses original \"strict\" or \"namespace-wide\" constraints, allowing the attacker to retarget and unseal the secret in any namespace or under any name to recover the plaintext credentials.","affected":[{"package":{"name":"sealed-secrets","ecosystem":"Bitnami","purl":"pkg:bitnami/sealed-secrets"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.36.0"}]}],"database_specific":{"source":"https://github.com/bitnami/vulndb/tree/main/data/sealed-secrets/BIT-sealed-secrets-2026-22728.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"}]}],"references":[{"type":"WEB","url":"https://github.com/bitnami-labs/sealed-secrets/security/advisories/GHSA-465p-v42x-3fmj"},{"type":"WEB","url":"https://www.cve.org/CVERecord?id=CVE-2026-22728"}],"database_specific":{"cpes":["cpe:2.3:*:sealed-secrets:sealed-secrets:*:*:*:*:*:*:*:*"],"severity":"Medium"}}