CVE-2026-26287High· 7.1▾ TwilightExternal Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Starting in version 0.10.0 and prior to version 1.3.2, a bug in the `webhook` generator initialization ord…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Starting in version 0.10.0 and prior to version 1.3.2, a bug in the webhook generator initialization order incorrectly cleared the label-enforcement flag (EnforceLabels) after it was set, resulting in the provider-side check for external-secrets.io/type=webhook being skipped (and the operation to succeed while it should have failed with secret does not contain needed label 'external-secrets.io/type: webhook'. Update secret label to use it with webhook. Version 1.3.2 contains a patch.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
github.com/external-secrets/external-secrets >= 0.10.0, < 1.3.2Patched in:
github.com/external-secrets/external-secrets 1.3.2Connected by shared product, vendor, weakness, or advisory.
CVE-2026-42876Medium· 4.9External Secrets Operator: Privilege escalation with secret overwriting
CVE-2026-105745Medium· 6.7Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem
CVE-2026-65100Medium· 4.8Apache Traffic Server updates the HTTP/2 HPACK dynamic table before confirming the header block encoded successfully, so an encode failure leaves the encoder out of sync with the peer decoder and corrupts subsequent header blocks on the …
CVE-2026-103353Medium· 5.3Incorrect Behavior Order vulnerability in WP ManageNinja LLC FluentForm fluentform allows Removing Important Client Functionality.This issue affects FluentForm: from n/a through 6.2.14.
CVE-2026-103012Low· 2.0Claude Code selected an API key stored by Claude Code, for example from an earlier `/login` or written directly to its configuration, ahead of the user's valid Claude Enterprise or Team sign-in when fetching the organization's server-man…
CVE-2026-93330Medium· 4.3Improper rule enforcement in the PAM Active Directory provider in Devolutions Server 2026.3.5 allows a user with PAM edit permissions to bypass the Devolutions Gateway host ruleset.