Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-26287— External Secrets Operator: label enforcement bypass in webhook generator enables secret exfiltration

Quick assessment

Affected
external-secrets external-secrets
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

External Secrets Operator 从第三方服务读取信息,并自动将其注入为 Kubernetes Secrets。在版本 0.10.0 至 1.3.2(不含)之间,webhook 生成器初始化顺序存在一个缺陷:在正确设置了标签强制启用标志( )之后,该标志又被错误地清除。这导致系统跳过了对 provider 端 标签的检查,从而使本应因缺少必要标签而失败的操作成功执行。正确的行为应是失败,并提示:“秘密中缺少所需标签 'external-secrets.io/type: webhook'。请更新秘密

CVSS 7.1 · High EPSS 0.24% · P14

Possible ATT&CK Techniques 1 AI

T1530 · Data from Cloud Storage

Affected Version Matrix 1

VendorProduct Version RangeStatus
external-secrets external-secrets >= 0.10.0, < 1.3.2 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-26287

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
External Secrets Operator: label enforcement bypass in webhook generator enables secret exfiltration
Source: CVE Program / CVE List V5
Vulnerability Description
External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Starting in version 0.10.0 and prior to version 1.3.2, a bug in the `webhook` generator initialization order incorrectly cleared the label-enforcement flag (`EnforceLabels`) after it was set, resulting in the provider-side check for `external-secrets.io/type=webhook` being skipped (and the operation to succeed while it should have failed with `secret does not contain needed label 'external-secrets.io/type: webhook'. Update secret label to use it with webhook`. Version 1.3.2 contains a patch.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
不正确的行为次序
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
external-secrets external-secrets >= 0.10.0, < 1.3.2 -

II. Public POCs for CVE-2026-26287

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-26287

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-26287 (1)

Vendor Advisories for CVE-2026-26287 (1)

Other References for CVE-2026-26287 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-26287

No comments yet


Leave a comment