Unauthorized Cross-Namespace Access in BeyondTrust Provider for External Secrets Operator
CVE-2025-62159
What is CVE-2025-62159?
A vulnerability in the BeyondTrust provider implementation for External Secrets Operator allows unauthorized access to Kubernetes secrets across namespaces. This security flaw, present in versions 0.10.1 through 0.19.2, enables the provider to retrieve secrets without validating the proper namespace context, putting sensitive credentials at risk. The issue has been remedied in version 0.20.0, which enforces namespace validation and restricts cross-namespace secret access to the ClusterSecretStore type only. Users are urged to upgrade to the latest version or implement policy engines such as Kyverno or OPA to mitigate potential threats.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
external-secrets >= 0.10.1, < 0.20.0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
