High severity7.1GHSA Advisory· Published Oct 6, 2026
CVE-2026-26287
CVE-2026-26287
Description
External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Starting in version 0.10.0 and prior to version 1.3.2, a bug in the webhook generator initialization order incorrectly cleared the label-enforcement flag (EnforceLabels) after it was set, resulting in the provider-side check for external-secrets.io/type=webhook being skipped (and the operation to succeed while it should have failed with secret does not contain needed label 'external-secrets.io/type: webhook'. Update secret label to use it with webhook. Version 1.3.2 contains a patch.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3>= 0.10.0, < 1.3.2+ 1 more
- (no CPE)range: >= 0.10.0, < 1.3.2
- (no CPE)
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-q7hv-xx6h-q2x8ghsaADVISORY
- github.com/external-secrets/external-secrets/commit/25aa09275861e3ed6fc5d2a1a60b9ac3df4a93banvd
- github.com/external-secrets/external-secrets/pull/5901nvd
- github.com/external-secrets/external-secrets/releases/tag/v1.3.2nvd
- github.com/external-secrets/external-secrets/security/advisories/GHSA-q7hv-xx6h-q2x8nvd
News mentions
0No linked articles in our index yet.