PT-2026-106770 · Unknown · External Secrets Operator

CVE-2026-26287

·

Published

2026-10-06

·

Updated

2026-10-07

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions External Secrets Operator versions 0.10.0 through 1.3.1
Description A bug in the webhook generator initialization order incorrectly clears the EnforceLabels label-enforcement flag after it has been set. This causes the provider-side check for the label external-secrets.io/type=webhook to be skipped, allowing operations to succeed when they should have failed. An attacker with permissions to create a webhook generator could potentially target a victim's secret that was not labeled for webhook use and exfiltrate its contents to a malicious URL.
Recommendations Update to version 1.3.2. Disable webhook generators if they are not required or deny generators.external-secrets.io/v1alpha1 Webhook via an admission policy. Restrict RBAC permissions to limit who can create generators of kind Webhook. Enforce an admission policy requiring referenced secrets to be labeled external-secrets.io/type=webhook. Restrict egress from external-secrets controller pods to an allowlist using a Kubernetes NetworkPolicy or service mesh egress policy.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-26287
GHSA-Q7HV-XX6H-Q2X8

Affected Products

External Secrets Operator