Unauthorized Cross-Namespace Access in BeyondTrust Provider for External Secrets Operator
CVE-2025-62159

8.7HIGH

Key Information:

Vendor
CVE Published:
10 October 2025

What is CVE-2025-62159?

A vulnerability in the BeyondTrust provider implementation for External Secrets Operator allows unauthorized access to Kubernetes secrets across namespaces. This security flaw, present in versions 0.10.1 through 0.19.2, enables the provider to retrieve secrets without validating the proper namespace context, putting sensitive credentials at risk. The issue has been remedied in version 0.20.0, which enforces namespace validation and restricts cross-namespace secret access to the ClusterSecretStore type only. Users are urged to upgrade to the latest version or implement policy engines such as Kyverno or OPA to mitigate potential threats.

Affected Version(s)

external-secrets >= 0.10.1, < 0.20.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-62159 : Unauthorized Cross-Namespace Access in BeyondTrust Provider for External Secrets Operator