Critical severity9.8NVD Advisory· Published Jul 24, 2024· Updated Jun 17, 2026
CVE-2024-36540
CVE-2024-36540
Description
Insecure permissions in external-secrets v0.9.16 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:external-secrets:external_secrets_operator:0.9.16:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:external-secrets:external_secrets_operator:0.9.16:*:*:*:*:*:*:*
- (no CPE)
- (no CPE)range: <=0.9.16
Patches
Vulnerability mechanics
References
1- gist.github.com/HouqiyuA/a4834f3c8450f9d89e2bc4d5c4beef6anvdThird Party Advisory
News mentions
0No linked articles in our index yet.