OFFLINE
Awaiting data
Security intelligence
MinorCritical vulnerability

CVE-2026-108728 (CVSS 7.1)

NVD · officialPublished Oct 11, 2026Risk 23/100

Flyte 2.0.1 through 2.0.51 contains a cleartext secret storage vulnerability that allows users with Pod read access to obtain secrets by reading init container environment variables. The embedded secret manager webhook writes base64-encoded FILE-mounted secret values into the SECRETS environment variable, letting principals without Secret store access decode them from the Pod spec.

CVSS
7.1
AV:NetworkAC:LowPR:LowUI:None

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source