---
id: CVE-2026-26287
title: >-
  External Secrets Operator reads information from a third-party service and
  automatically injects the values as Kubernetes Secrets
summary: >-
  External Secrets Operator reads information from a third-party service and
  automatically injects the values as Kubernetes Secrets. Starting in version
  0.10.0 and prior to version 1.3.2, a bug in the `webhook` generator
  initialization ord…
severity: high
cvss: 7.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'
cwe:
  - CWE-696
vendor: external-secrets
product: external-secrets
affected:
  - 'external-secrets >= 0.10.0, < 1.3.2'
patched:
  - github.com/external-secrets/external-secrets 1.3.2
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T18:16:54.047'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-26287'
references:
  - url: >-
      https://github.com/external-secrets/external-secrets/commit/25aa09275861e3ed6fc5d2a1a60b9ac3df4a93ba
    label: security-advisories@github.com
  - url: 'https://github.com/external-secrets/external-secrets/pull/5901'
    label: security-advisories@github.com
  - url: 'https://github.com/external-secrets/external-secrets/releases/tag/v1.3.2'
    label: security-advisories@github.com
  - url: >-
      https://github.com/external-secrets/external-secrets/security/advisories/GHSA-q7hv-xx6h-q2x8
    label: security-advisories@github.com
  - url: 'https://github.com/advisories/GHSA-q7hv-xx6h-q2x8'
tags:
  - nvd
  - cve.org
  - ghsa
  - go
aliases:
  - GHSA-q7hv-xx6h-q2x8
ecosystem: go
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-10-06T17:21:33.262411Z'
ingestedAt: '2026-10-06T16:04:04.481Z'
---

## Overview

External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Starting in version 0.10.0 and prior to version 1.3.2, a bug in the `webhook` generator initialization order incorrectly cleared the label-enforcement flag (`EnforceLabels`) after it was set, resulting in the provider-side check for `external-secrets.io/type=webhook` being skipped (and the operation to succeed while it should have failed with `secret does not contain needed label 'external-secrets.io/type: webhook'. Update secret label to use it with webhook`. Version 1.3.2 contains a patch.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-26287)

Affected packages:

- `github.com/external-secrets/external-secrets >= 0.10.0, < 1.3.2`

Patched in:

- `github.com/external-secrets/external-secrets 1.3.2`

Source: https://github.com/advisories/GHSA-q7hv-xx6h-q2x8
