OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-26287: External Secrets Operator: label enforcement bypass in webhook generator enables secret exfiltration

GitHub Advisories · officialPublished Oct 6, 2026Risk 37/100

## Summary A bug in the `webhook` generator initialization order incorrectly cleared the label-enforcement flag (`EnforceLabels`) after it was set, resulting in the provider-side check for `external-secrets.io/type=webhook` being skipped (and the operation to succeed while it should have failed with `secret does not contain needed label 'external-secrets.io/type: webhook'. Update secret label to use it with webhook`. ## Impact A user with the permission to create webhook generator can set the webhook generator to a victim' secret (which was not previously labelled for webhook's use), and exfiltrate it to a malicious URL. ## Mitigations Until you upgrade, you can reduce risk by: - disabling webhook generators if not needed (or denying `generators.external-secrets.io/v1alpha1` `Webhook` via an admission policy); - restricting RBAC: limit who can create generators of kind `Webhook`; - enforcing an admission policy (OPA Gatekeeper / Kyverno) requiring referenced secrets to be labeled `external-secrets.io/type=webhook`; - restricting egress from external-secrets controller pods to an allowlist (kubernetes `NetworkPolicy` / service mesh egress policy). ## References - PR #5901 (fix: webhook initialization order)

Upgrade affected packages to a patched version: github.com/external-secrets/external-secrets 1.3.2.

Vendor
Not specified
Product
github.com/external-secrets/external-secrets
Exploitation
none known
Evidence
official
CVSS
7.1

This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source