Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-q7hv-xx6h-q2x8 | External Secrets Operator: label enforcement bypass in webhook generator enables secret exfiltration |
Wed, 07 Oct 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Wed, 07 Oct 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
External-secrets
External-secrets external-secrets |
|
| Vendors & Products |
External-secrets
External-secrets external-secrets |
Tue, 06 Oct 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 06 Oct 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Starting in version 0.10.0 and prior to version 1.3.2, a bug in the `webhook` generator initialization order incorrectly cleared the label-enforcement flag (`EnforceLabels`) after it was set, resulting in the provider-side check for `external-secrets.io/type=webhook` being skipped (and the operation to succeed while it should have failed with `secret does not contain needed label 'external-secrets.io/type: webhook'. Update secret label to use it with webhook`. Version 1.3.2 contains a patch. | |
| Title | External Secrets Operator: label enforcement bypass in webhook generator enables secret exfiltration | |
| Weaknesses | CWE-696 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-06T17:21:44.292Z
Reserved: 2026-02-12T17:10:53.415Z
Link: CVE-2026-26287
Updated: 2026-10-06T17:21:39.487Z
Status : Awaiting Analysis
Published: 2026-10-06T16:17:07.180
Modified: 2026-10-06T20:03:40.690
Link: CVE-2026-26287
OpenCVE Enrichment
Updated: 2026-10-07T14:00:17Z
Github GHSA