CVE-2026-105165 | devopspolis secrets-replicator up to 0.4.0 AssumeRole src/handler.py process_single_secret external_id permission assignment

SecurityVulns

A vulnerability was found in devopspolis secrets-replicator up to 0.4.0 and classified as critical. Impacted is the function process_single_secret of the file src/handler.py of the component AssumeRole Handler. Such manipulation of the argument external_id leads to incorrect permission assignment.

This vulnerability is documented as CVE-2026-105165. The attack can be executed remotely. There is not any exploit available.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More