Skip to content

Build1 publisherNot yet confirmed elsewhere2 min readPublished

Seven calls to a secret, with zero Secrets Manager permissions on paper

A CloudGoat walkthrough moves an API key through SNS into API Gateway and back out of Lambda. Access Analyzer and PMapper both report the user has no access.

The Engineer · Build desk

How we use AISend a correction

Illustration accompanying Seven calls to a secret, with zero Secrets Manager permissions on paper
Generated illustration

What happened

  • A 2025 CloudGoat walkthrough shows an IAM user with no Secrets Manager permissions retrieving a secret in seven API calls.
  • The route: an SNS topic publishes an API Gateway key, the user subscribes and reads it, and the gateway's Lambda integration returns the secret as the HTTP body.
  • The topic carries no resource policy, so the user's own sns:Subscribe on Resource "*" is the only gate on subscription.
  • A Z3 run over 24 API Gateway management paths finds 21 still reachable despite seven carefully chosen deny patterns.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • constraint A review that asks which principals can call secretsmanager:GetSecretValue will keep answering correctly and uselessly, because the link between the services is a value in a payload and not a...
  • decision Path-by-path denial on apigateway:GET is the wrong shape to bet on; the reconnaissance an attacker actually needs sits on the mundane paths nobody thought to name.
  • precedent Controls that only read resource policies will keep coming back clean, which pushes the work into asset inventory: what a channel carries has to be a recorded field, not a reviewer's assumption.

A permission graph is assembled from edges that policies name. IAM Access Analyzer and PMapper both report that the IAM user cannot read any secret in the account [4], and on the evidence those tools consume they are correct: nothing grants that user Secrets Manager access [3], and no statement anywhere joins SNS to Secrets Manager [7]. The join is an API key sitting in a message payload [6]. A key in a payload is data, and data is not an edge, so there is no node to traverse and the answer comes back clean.

The deny list is the part worth studying, because it is what a careful reviewer actually produces. The user's policy allows `apigateway:GET` on `Resource: "*"` and then denies it on seven specific patterns covering API keys, method bodies and integration internals [8]. Run those seven patterns against the 24 management paths the prover walks, and 21 stay reachable [13]: three blocked [15], which leaves 87.5 percent of the enumerated surface open [16]. The paths that matter are among the open ones. `/restapis` lists the API IDs, `/restapis/{id}/resources` lists the paths, `/restapis/{id}/stages` lists the stages, and with those three the attacker has the full URL [14]. Three calls of reconnaissance against a documented chain of seven [17]. The integration body, the thing the deny list did protect, was never on the route.

The result is awkward for the tooling that produced it. Stave's existing broad-subscribe control inspects the topic's resource policy [2], and this topic has no resource policy, which in AWS leaves the identity policy as the sole gate [9]. A control that reads resource policies has nothing to read. The SAT verdict came instead from three facts held together: the identity policy, the missing topic policy, and an annotation on the asset recording that the topic publishes an `api_key` [1], with the witness naming both the topic and the REST API the key targets [12].

One synthetic CloudGoat user in one lab account is not a fleet [18], and the modelling work here is a prover run over a writeup, not a survey of production estates [11]. What generalises is narrower and more useful than a new attack class: the grant that ends up exercised is the Lambda execution role [10], written for the function, and it becomes the effective permission set of whoever can obtain the key that fronts it. Nothing in the four service configurations is misconfigured by its own checklist [7]. The defect is the pairing of a subscribable channel with a payload that carries authentication material, and no per-service review has a place to record that pairing.

What to watch

  • Whether the four queries against the remediated configuration all return UNSAT; the writeup reports only the four against the vulnerable version.
  • Whether Stave reshapes its broad-subscribe control into an identity-policy-plus-annotation check instead of a resource-policy check.
  • Whether anyone reproduces the seven-call chain outside the CloudGoat lab account, on a real estate with real topics.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence52
Adoption
Insufficient
Hype gap+34
Incentives72
Confidence46
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    The data-flow annotation publishes_credential_type=api_key on the topic asset is what makes this a security concern rather than a subscription pattern concern.

  2. [2]

    Stave's existing broad-subscribe control checks the topic's resource policy, whereas this issue lives in the IAM identity policy plus the absence of a topic policy plus the data-flow fact about what the topic publishes.

  3. [3]

    The synthetic IAM user cg-sns-user-cgidxi93qpes3g has zero permissions on Secrets Manager.

    ReportedSupportedView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. dev.to

    1 article · August 24, 2026

    Zero Permissions on Secrets Manager. Full Access to Your Secrets.

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

Loading related stories