PT-2026-106770 · Unknown · External Secrets Operator
CVE-2026-26287
·
Published
2026-10-06
·
Updated
2026-10-07
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
External Secrets Operator versions 0.10.0 through 1.3.1
Description
A bug in the
webhook generator initialization order incorrectly clears the EnforceLabels label-enforcement flag after it has been set. This causes the provider-side check for the label external-secrets.io/type=webhook to be skipped, allowing operations to succeed when they should have failed. An attacker with permissions to create a webhook generator could potentially target a victim's secret that was not labeled for webhook use and exfiltrate its contents to a malicious URL.Recommendations
Update to version 1.3.2.
Disable webhook generators if they are not required or deny
generators.external-secrets.io/v1alpha1 Webhook via an admission policy.
Restrict RBAC permissions to limit who can create generators of kind Webhook.
Enforce an admission policy requiring referenced secrets to be labeled external-secrets.io/type=webhook.
Restrict egress from external-secrets controller pods to an allowlist using a Kubernetes NetworkPolicy or service mesh egress policy.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
External Secrets Operator