{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/external-secrets/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:external-secrets:external_secrets:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.1,"id":"CVE-2026-26287"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["External Secrets Operator (\u003e= 0.10.0, \u003c 1.3.2)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","cloud-native","k8s"],"_cs_type":"advisory","_cs_vendors":["External Secrets"],"content_html":"\u003cp\u003eExternal Secrets Operator is vulnerable to an authentication and authorization bypass affecting its \u003ccode\u003ewebhook\u003c/code\u003e generator functionality. The issue arises from an incorrect initialization order in the provider's logic, which inadvertently disables the \u003ccode\u003eEnforceLabels\u003c/code\u003e flag after it has been configured. This flag is intended to ensure that only secrets explicitly labeled with \u003ccode\u003eexternal-secrets.io/type: webhook\u003c/code\u003e can be utilized by the webhook generator.\u003c/p\u003e\n\u003cp\u003eBy exploiting this defect, a low-privileged user or service account with the ability to create \u003ccode\u003eWebhook\u003c/code\u003e generator resources can reference any Kubernetes secret within the cluster, regardless of whether it carries the required security label. When the operator processes the request, it skips the validation check and transmits the secret data to an attacker-controlled endpoint defined in the webhook configuration. This affects External Secrets Operator versions 0.10.0 through 1.3.1. The fix was introduced in version 1.3.2.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the exfiltration of sensitive Kubernetes secrets, including API keys, database credentials, or tokens stored within the cluster. This threat specifically targets clusters where users have delegated permissions to create webhook generators. If unauthorized actors gain access to this capability, they can extract credentials that were previously protected by namespace or label-based access control, potentially leading to privilege escalation or lateral movement within the environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the External Secrets Operator to version 1.3.2 or later to remediate CVE-2026-26287.\u003c/li\u003e\n\u003cli\u003eImplement an admission policy using OPA Gatekeeper or Kyverno to explicitly enforce the presence of the \u003ccode\u003eexternal-secrets.io/type=webhook\u003c/code\u003e label on all secrets referenced by \u003ccode\u003eWebhook\u003c/code\u003e generator objects.\u003c/li\u003e\n\u003cli\u003eReview RBAC configurations to strictly limit the \u003ccode\u003ecreate\u003c/code\u003e or \u003ccode\u003epatch\u003c/code\u003e permissions on \u003ccode\u003egenerators.external-secrets.io/v1alpha1\u003c/code\u003e resources.\u003c/li\u003e\n\u003cli\u003eApply Kubernetes NetworkPolicies or service mesh egress filters to restrict the External Secrets Operator pod to only communicate with known, trusted webhook destinations.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-06T18:48:44Z","date_published":"2026-10-06T18:48:44Z","id":"https://feed.craftedsignal.io/briefs/2026-10-external-secrets-bypass/","summary":"A vulnerability in the External Secrets Operator enables authenticated users to bypass label enforcement checks in webhook generators, allowing unauthorized exfiltration of Kubernetes secrets to malicious URLs.","title":"External Secrets Operator Label Enforcement Bypass Leading to Secret Exfiltration","url":"https://feed.craftedsignal.io/briefs/2026-10-external-secrets-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - External Secrets","version":"https://jsonfeed.org/version/1.1"}