<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>K8s - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/k8s/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 06 Oct 2026 18:48:44 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/k8s/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>External Secrets Operator Label Enforcement Bypass Leading to Secret Exfiltration</title><link>https://feed.craftedsignal.io/briefs/2026-10-external-secrets-bypass/</link><pubDate>Tue, 06 Oct 2026 18:48:44 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-external-secrets-bypass/</guid><description>A vulnerability in the External Secrets Operator enables authenticated users to bypass label enforcement checks in webhook generators, allowing unauthorized exfiltration of Kubernetes secrets to malicious URLs.</description><content:encoded><![CDATA[<p>External Secrets Operator is vulnerable to an authentication and authorization bypass affecting its <code>webhook</code> generator functionality. The issue arises from an incorrect initialization order in the provider's logic, which inadvertently disables the <code>EnforceLabels</code> flag after it has been configured. This flag is intended to ensure that only secrets explicitly labeled with <code>external-secrets.io/type: webhook</code> can be utilized by the webhook generator.</p>
<p>By exploiting this defect, a low-privileged user or service account with the ability to create <code>Webhook</code> generator resources can reference any Kubernetes secret within the cluster, regardless of whether it carries the required security label. When the operator processes the request, it skips the validation check and transmits the secret data to an attacker-controlled endpoint defined in the webhook configuration. This affects External Secrets Operator versions 0.10.0 through 1.3.1. The fix was introduced in version 1.3.2.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for the exfiltration of sensitive Kubernetes secrets, including API keys, database credentials, or tokens stored within the cluster. This threat specifically targets clusters where users have delegated permissions to create webhook generators. If unauthorized actors gain access to this capability, they can extract credentials that were previously protected by namespace or label-based access control, potentially leading to privilege escalation or lateral movement within the environment.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for security teams:</p>
<ul>
<li>Upgrade the External Secrets Operator to version 1.3.2 or later to remediate CVE-2026-26287.</li>
<li>Implement an admission policy using OPA Gatekeeper or Kyverno to explicitly enforce the presence of the <code>external-secrets.io/type=webhook</code> label on all secrets referenced by <code>Webhook</code> generator objects.</li>
<li>Review RBAC configurations to strictly limit the <code>create</code> or <code>patch</code> permissions on <code>generators.external-secrets.io/v1alpha1</code> resources.</li>
<li>Apply Kubernetes NetworkPolicies or service mesh egress filters to restrict the External Secrets Operator pod to only communicate with known, trusted webhook destinations.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>cloud-native</category><category>k8s</category></item></channel></rss>