Webhooks Vulnerability in External Secrets Operator for Kubernetes by External Secrets
CVE-2026-26287
7.1HIGH
What is CVE-2026-26287?
The External Secrets Operator for Kubernetes has a vulnerability that affects versions 0.10.0 up to 1.3.1. A flaw in the webhook generator’s initialization process leads to the incorrect clearing of the label enforcement flag, allowing operations to proceed that should otherwise fail when the required label 'external-secrets.io/type: webhook' is missing. Users are recommended to upgrade to version 1.3.2, which includes a fix for this issue.
Affected Version(s)
external-secrets >= 0.10.0, < 1.3.2
