{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/vault-secrets-webhook-1.22.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.6,"id":"CVE-2026-54725"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["vault-secrets-webhook (1.22.2)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"threat","_cs_vendors":["Banzai Cloud"],"content_html":"\u003cp\u003eThe Banzai Cloud vault-secrets-webhook (versions \u0026lt;= 1.22.2) contains a critical vulnerability (CVE-2026-54725) that enables Server-Side Request Forgery (SSRF) and cluster-wide privilege escalation. The webhook improperly validates the \u003ccode\u003evault.security.banzaicloud.io/vault-addr\u003c/code\u003e annotation on Kubernetes ConfigMaps and Secrets. When an attacker creates or updates these resources with a \u003ccode\u003evault:\u003c/code\u003e prefix, the webhook's admission handler synchronously invokes a request to the user-supplied URL.\u003c/p\u003e\n\u003cp\u003eBeyond the SSRF, the webhook holds excessive cluster-wide \u003ccode\u003eserviceaccounts/token:create\u003c/code\u003e permissions. When combined with the \u003ccode\u003evault-serviceaccount\u003c/code\u003e annotation, an attacker can coerce the webhook to generate a token for any ServiceAccount and transmit that JWT to an attacker-controlled server. This enables attackers to impersonate authorized ServiceAccounts and access sensitive data from the Vault instance. The attack occurs during the admission review process, making it highly effective for users with standard namespace access rights.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker creates or updates a ConfigMap or Secret in a namespace monitored by the vault-secrets-webhook.\u003c/li\u003e\n\u003cli\u003eAttacker injects the \u003ccode\u003evault.security.banzaicloud.io/vault-addr\u003c/code\u003e annotation with an attacker-controlled URL or internal metadata endpoint (e.g., 169.254.169.254).\u003c/li\u003e\n\u003cli\u003eAttacker specifies \u003ccode\u003evault.security.banzaicloud.io/vault-serviceaccount\u003c/code\u003e pointing to a target ServiceAccount to be exfiltrated.\u003c/li\u003e\n\u003cli\u003eWebhook admission handler intercepts the request and parses the malicious annotations during the admission review cycle.\u003c/li\u003e\n\u003cli\u003eWebhook uses its cluster-wide RBAC permissions to call \u003ccode\u003eCoreV1().ServiceAccounts().CreateToken\u003c/code\u003e for the requested ServiceAccount.\u003c/li\u003e\n\u003cli\u003eWebhook initiates a synchronous HTTP request via \u003ccode\u003evault.NewClientFromConfigWithContext\u003c/code\u003e to the attacker-defined URL.\u003c/li\u003e\n\u003cli\u003eThe sensitive ServiceAccount JWT is transmitted via the Authorization header to the attacker-controlled server.\u003c/li\u003e\n\u003cli\u003eAttacker replays the captured JWT against the Vault instance to access unauthorized secrets.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the exfiltration of high-privilege ServiceAccount JWTs, leading to complete credential compromise of Vault-managed secrets. Attackers can leverage the webhook's privileged network position to probe internal network infrastructure and cloud metadata services, potentially escalating access within the cloud environment. This vulnerability affects all environments running the vault-secrets-webhook where users have standard resource creation permissions in monitored namespaces.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch the vault-secrets-webhook to version 1.22.3 or higher to incorporate input validation for the vault-addr annotation and improved security controls.\u003c/li\u003e\n\u003cli\u003eAudit current ClusterRole definitions for the vault-secrets-webhook to restrict \u003ccode\u003eserviceaccounts/token:create\u003c/code\u003e permissions to the minimum necessary scope.\u003c/li\u003e\n\u003cli\u003eUse network policies to restrict egress traffic from the webhook pod to only allow communication with known, legitimate Vault server endpoints.\u003c/li\u003e\n\u003cli\u003eMonitor Kubernetes audit logs for ConfigMap and Secret operations containing the specified vault-security annotations.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-31T19:20:21Z","date_published":"2026-07-31T19:20:21Z","id":"https://feed.craftedsignal.io/briefs/2026-07-vault-secrets-webhook-ssrf/","summary":"The vault-secrets-webhook is vulnerable to SSRF and ServiceAccount token theft due to unvalidated annotation handling, allowing attackers to exfiltrate JWTs via unauthorized outbound requests.","title":"SSRF and Credential Exfiltration in vault-secrets-webhook","url":"https://feed.craftedsignal.io/briefs/2026-07-vault-secrets-webhook-ssrf/"}],"language":"en","title":"CraftedSignal Threat Feed - Vault-Secrets-Webhook (1.22.2)","version":"https://jsonfeed.org/version/1.1"}