Kubernetes Mutating Webhook Vulnerability in vault-secrets-webhook by Banzaicloud
CVE-2026-54725
9.6CRITICAL
What is CVE-2026-54725?
The vault-secrets-webhook is a Kubernetes mutating webhook that allows direct secret injection into Pods. In versions prior to 1.23.1, the function parseVaultConfig() accepts annotations that can lead to a ServiceAccount JWT being sent to an attacker-controlled Vault address. This could potentially compromise sensitive credentials. Users are advised to upgrade to version 1.23.1 or later to mitigate this risk.
Affected Version(s)
vault-secrets-webhook < 1.23.1
