{"id":"CVE-2026-26287","title":"External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets","summary":"External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Starting in version 0.10.0 and prior to version 1.3.2, a bug in the `webhook` generator initialization ord…","severity":"high","cvss":7.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","cwe":["CWE-696"],"vendor":"external-secrets","product":"external-secrets","affected":["external-secrets >= 0.10.0, < 1.3.2"],"patched":["github.com/external-secrets/external-secrets 1.3.2"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T18:16:54.047","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-26287","references":[{"url":"https://github.com/external-secrets/external-secrets/commit/25aa09275861e3ed6fc5d2a1a60b9ac3df4a93ba","label":"security-advisories@github.com"},{"url":"https://github.com/external-secrets/external-secrets/pull/5901","label":"security-advisories@github.com"},{"url":"https://github.com/external-secrets/external-secrets/releases/tag/v1.3.2","label":"security-advisories@github.com"},{"url":"https://github.com/external-secrets/external-secrets/security/advisories/GHSA-q7hv-xx6h-q2x8","label":"security-advisories@github.com"},{"url":"https://github.com/advisories/GHSA-q7hv-xx6h-q2x8"}],"tags":["nvd","cve.org","ghsa","go"],"aliases":["GHSA-q7hv-xx6h-q2x8"],"ecosystem":"go","ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-10-06T17:21:33.262411Z"},"ingestedAt":"2026-10-06T16:04:04.481Z","slug":"CVE-2026-26287","body":"## Overview\n\nExternal Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Starting in version 0.10.0 and prior to version 1.3.2, a bug in the `webhook` generator initialization order incorrectly cleared the label-enforcement flag (`EnforceLabels`) after it was set, resulting in the provider-side check for `external-secrets.io/type=webhook` being skipped (and the operation to succeed while it should have failed with `secret does not contain needed label 'external-secrets.io/type: webhook'. Update secret label to use it with webhook`. Version 1.3.2 contains a patch.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-26287)\n\nAffected packages:\n\n- `github.com/external-secrets/external-secrets >= 0.10.0, < 1.3.2`\n\nPatched in:\n\n- `github.com/external-secrets/external-secrets 1.3.2`\n\nSource: https://github.com/advisories/GHSA-q7hv-xx6h-q2x8","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":39.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}