AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-26287.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSHIGH / 0No severity score in this snapshot.
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Oct 06, 2026

Disclosure summary

## Summary A bug in the `webhook` generator initialization order incorrectly cleared the label-enforcement flag (`EnforceLabels`) after it was set, resulting in the provider-side check for `external-secrets.io/type=webhook` being skipped (and the operation to succeed while it should have failed with `secret does not contain needed label 'external-secrets.io/type: webhook'. Update secret label to use it with webhook`. ## Impact A user with the permission to create webhook generator can set the webhook generator to a victim' secret (which was not previously labelled for webhook's use), and exfiltrate it to a malicious URL. ## Mitigations Until you upgrade, you can reduce risk by: - disabling webhook generators if not needed (or denying `generators.external-secrets.io/v1alpha1` `Webhook` via an admission policy); - restricting RBAC: limit who can create generators of kind `Webhook`; - enforcing an admission policy (OPA Gatekeeper / Kyverno) requiring referenced secrets to be labeled `external-secrets.io/type=webhook`; - restricting egress from external-secrets controller pods to an allowlist (kubernetes `NetworkPolicy` / service mesh egress policy). ## References - PR #5901 (fix: webh

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-q7hv-xx6h-q2x8

Open original source · Updated Oct 06, 2026

External Secrets Operator: label enforcement bypass in webhook generator enables secret exfiltration

Source severity: HIGH / 0

EcosystemPackageAffected rangeFirst patched
gogithub.com/external-secrets/external-secrets>= 0.10.0, < 1.3.21.3.2

Original records & references

PUBLISHED 2026-10-06T11:29:25-04:00
MODIFIED 2026-10-06T11:29:26-04:00
INGESTED 2026-10-06T11:45:43-04:00