CVE-2026-26287: External Secrets Operator: label enforcement bypass in webhook generator enables secret exfiltration
## Summary A bug in the `webhook` generator initialization order incorrectly cleared the label-enforcement flag (`EnforceLabels`) after it was set, resulting in the provider-side check for `external-secrets.io/type=webhook` being skipped (and the operation to succeed while it should have failed with `secret does not contain needed label 'external-secrets.io/type: webhook'. Update secret label to use it with webhook`. ## Impact A user with the permission to create webhook generator can set the webhook generator to a victim' secret (which was not previously labelled for webhook's use), and exfiltrate it to a malicious URL. ## Mitigations Until you upgrade, you can reduce risk by: - disabling webhook generators if not needed (or denying `generators.external-secrets.io/v1alpha1` `Webhook` via an admission policy); - restricting RBAC: limit who can create generators of kind `Webhook`; - enforcing an admission policy (OPA Gatekeeper / Kyverno) requiring referenced secrets to be labeled `external-secrets.io/type=webhook`; - restricting egress from external-secrets controller pods to an allowlist (kubernetes `NetworkPolicy` / service mesh egress policy). ## References - PR #5901 (fix: webhook initialization order)
Recommended action
Recommended action
Upgrade affected packages to a patched version: github.com/external-secrets/external-secrets 1.3.2.
Technical details
- Vendor
- Not specified
- Product
- github.com/external-secrets/external-secrets
- Exploitation
- none known
- Evidence
- official
Evidence and sources
This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source