CVE-2026-26287
Received Received - Intake

External Secrets Operator Label Enforcement Bypass

Vulnerability report for CVE-2026-26287, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: GitHub, Inc.

Description

External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Starting in version 0.10.0 and prior to version 1.3.2, a bug in the `webhook` generator initialization order incorrectly cleared the label-enforcement flag (`EnforceLabels`) after it was set, resulting in the provider-side check for `external-secrets.io/type=webhook` being skipped (and the operation to succeed while it should have failed with `secret does not contain needed label 'external-secrets.io/type: webhook'. Update secret label to use it with webhook`. Version 1.3.2 contains a patch.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
external-secrets external-secrets >= 0.10.0, < 1.3.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-696 The product performs multiple related behaviors, but the behaviors are performed in the wrong order in ways that may produce resultant weaknesses.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the External Secrets Operator, which reads data from third-party services and creates Kubernetes Secrets. A bug in versions 0.10.0 to 1.3.1 incorrectly clears a security flag during setup, allowing secrets without required labels to be processed as valid webhook secrets. This bypasses a critical security check.

Detection Guidance

To detect this vulnerability, check if your External Secrets Operator version is between 0.10.0 and 1.3.1. Run: kubectl get deployment -n external-secrets external-secrets -o jsonpath='{.spec.template.spec.containers[0].image}' to verify the version. If the version is in this range, the system is vulnerable.

Impact Analysis

If exploited, this flaw could allow unauthorized secrets to be created or modified without proper label validation. This may lead to data leaks, unauthorized access to sensitive information, or compliance violations due to improper secret management in Kubernetes environments.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating confidentiality requirements in GDPR and HIPAA. Improper secret management may result in non-compliance with data protection regulations, potentially leading to legal penalties or breaches of trust.

Mitigation Strategies

Update External Secrets Operator to version 1.3.2 or later to patch the bug in the webhook generator initialization that incorrectly clears the label-enforcement flag.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-26287. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart