Sceawere

Vulnerability Detail

CVE-2026-105165UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Incorrect Permission Assignment in secrets-replicator

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.3
Creation Date
19h ago
Vendor
devopspolis
Product
secrets-replicator
Attack Type
Incorrect Permission Assignment
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability has been found in devopspolis secrets-replicator up to 0.4.0. Impacted is the function process_single_secret of the file src/handler.py of the component AssumeRole Handler. Such manipulation of the argument external_id leads to incorrect permission assignment. The attack can be executed remotely. Upgrading to version 0.5.0 is recommended to address this issue. The name of the patch is b42239405fbf4fae3c3f0048fc0b4225112edceb. It is suggested to upgrade the affected component.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.3",
  "pubDate": "2026-10-04T23:16:58.180Z",
  "pubdate": "2026-10-04T23:16:58.180Z",
  "executiveSummary": "A critical vulnerability exists in devopspolis secrets-replicator up to version 0.4.0, involving improper handling of the external_id argument within the AssumeRole Handler. This flaw leads to incorrect permission assignment during the replication process. The vulnerability is exploitable remotely by unauthenticated or unauthorized actors, depending on the implementation context, posing a significant risk to the integrity and confidentiality of sensitive secrets managed by the application. Successful exploitation allows an attacker to manipulate the authentication or authorization flow, potentially resulting in unauthorized access to restricted AWS resources or secrets. The risk is considered high due to the potential for privilege escalation and the exposure of sensitive credentials managed by the replication service. Users are strongly advised to upgrade to version 0.5.0 to mitigate the identified security deficiency.",
  "technicalDetails": "The vulnerability resides in the process_single_secret function located within src/handler.py in the AssumeRole Handler component of secrets-replicator. The root cause is an improper validation or sanitization mechanism applied to the external_id parameter used during the AWS STS AssumeRole operation.\nIn cloud environments, the external_id is a crucial security mechanism designed to prevent the 'confused deputy' problem when a third party is assuming a role in an account they do not own. By manipulating the external_id argument, an attacker can influence the policy evaluation or resource access logic of the AssumeRole request.\nThe attack flow initiates when the secrets-replicator component processes a request containing a malicious or crafted external_id. Because the application fails to enforce strict constraints on this input within the process_single_secret function, the resulting AWS API call may include an arbitrary or unintended external_id value. If the trust policy of the target IAM role is misconfigured or if the logic flow allows for a bypass based on this input manipulation, the application assumes a role with permissions that do not align with the intended scope of the replication process.\nThis represents a logic flaw in the handling of identity-related parameters. The exploit does not necessarily require complex payload injection; rather, it exploits the semantic misalignment between the input provided to the handler and the subsequent execution of the AssumeRole protocol. When the system processes the request, the resultant session is granted privileges based on the manipulated context. Consequently, this leads to an incorrect permission assignment, potentially granting the secrets-replicator instance broader access than required or access to resources it should not be authorized to manage.\nPost-exploitation, an attacker can leverage the over-privileged session to exfiltrate, modify, or delete secrets across the AWS environment. The impact is essentially a privilege escalation that bypasses the restrictive security controls intended to compartmentalize the replication service's access. The exposure is network-reachable, meaning any actor capable of triggering the secret replication flow can initiate this attack. The patch identified as b42239405fbf4fae3c3f0048fc0b4225112edceb specifically addresses this validation failure."
}
CVE-2026-105165: Incorrect Permission Assignment in secrets-replicator (MEDIUM Severity, CVSS: 6.3) | Sceawere