Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-q7hv-xx6h-q2x8 | External Secrets Operator: label enforcement bypass in webhook generator enables secret exfiltration |
Tue, 06 Oct 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Starting in version 0.10.0 and prior to version 1.3.2, a bug in the `webhook` generator initialization order incorrectly cleared the label-enforcement flag (`EnforceLabels`) after it was set, resulting in the provider-side check for `external-secrets.io/type=webhook` being skipped (and the operation to succeed while it should have failed with `secret does not contain needed label 'external-secrets.io/type: webhook'. Update secret label to use it with webhook`. Version 1.3.2 contains a patch. | |
| Title | External Secrets Operator: label enforcement bypass in webhook generator enables secret exfiltration | |
| Weaknesses | CWE-696 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-06T17:21:44.292Z
Reserved: 2026-02-12T17:10:53.415Z
Link: CVE-2026-26287
No data.
Status : Received
Published: 2026-10-06T16:17:07.180
Modified: 2026-10-06T16:17:07.180
Link: CVE-2026-26287
No data.
OpenCVE Enrichment
No data.
-
CWE-696
Incorrect Behavior Order
Github GHSA