1sealsemantic last-mile verification

Research / Finding

Label enforcement bypass in webhook generator enables secret exfiltration

F-ESO-LABELBYPASS-001

Public snapshot: 8 Oct 2026. Status, releases and attribution belong to each source below; none is inferred from another record.

Read the evidence · View in research browse

Recorded evidence

7.1high
GHSA-q7hv-xx6h-q2x8GHSAexternal-secrets/external-secrets

Label enforcement bypass in webhook generator enables secret exfiltration

Upstream fixed versions: github.com/external-secrets/external-secrets: v1.3.2; v2.0.0+

CVE-2026-26287: RESERVED; not counted as a published CVE

patched
details
Finding IDs
F-ESO-LABELBYPASS-001
CVE
CVE-2026-26287
GHSA
GHSA-q7hv-xx6h-q2x8
Status
patched
Fixed in
external-secrets v1.3.2; v2.0.0+
Recorded credit
@1seal: reporter (accepted); @evrardj-roche: reporter; @gusfcarvalho: remediation developer
Note
GHSA-q7hv-xx6h-q2x8 was published on 2026-10-06 and credits @1seal as a reporter. Webhook generator initialization clears EnforceLabels, allowing an authorized generator creator to reference an unlabeled same-namespace Secret for an outbound webhook. GitHub lists CVE-2026-26287, but the CVE List entry remained RESERVED at the recorded check; this advisory is counted as a published GHSA, not a published CVE, until that state changes.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
CVE registry state
RESERVED
CVE state checked
CVSS assessment
external-secrets GitHub advisory; v3.1; 7.1; observed 2026-10-06
Upstream title
Label enforcement bypass in webhook generator enables secret exfiltration
Upstream publication
Upstream updated
Metadata fetched
Upstream fixed versions
github.com/external-secrets/external-secrets: v1.3.2; v2.0.0+
Upstream affected ranges
github.com/external-secrets/external-secrets: v0.10.0–v1.3.1
Upstream @1seal credit
@1seal: reporter (accepted)

F-ESO-LABELBYPASS-001: Access control. The recorded webhook initialization-order fix concerns bypassing the intended validation policy. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.

Mechanism source for F-ESO-LABELBYPASS-001

Security area (1seal assessment): Authorization. Webhook generator initialization bypasses the intended secret-label authorization gate. Reviewed 6 Oct 2026.

—score not recorded
external-secrets/external-secrets #5901Reported fixexternal-secrets/external-secrets

fix: webhook initialization order

merged
details
Finding IDs
F-ESO-LABELBYPASS-001
Status
merged
Disclosure date
Note
Public PR #5901 fixes webhook generator initialization order. The linked GHSA-q7hv-xx6h-q2x8 was published on 2026-10-06 and credits @1seal as a reporter; the PR and advisory are separate evidence for one finding.

F-ESO-LABELBYPASS-001: Access control. The recorded webhook initialization-order fix concerns bypassing the intended validation policy. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.

Mechanism source for F-ESO-LABELBYPASS-001

Security area (1seal assessment): Authorization. The recorded webhook initialization-order fix concerns bypassing the intended validation policy. Reviewed 24 Sep 2026.

Clarify or correct this record privately. The email subject includes the finding ID. For an existing case, continue the agreed private thread. Do not post unpublished vulnerability details in public issues. Research disclosure policy.

How this page groups evidence

This identifier groups recorded evidence; it is not an additional CVE, independent-vulnerability count or guarantee of vendor confirmation. Fixed code, released versions, attribution and independent discovery are distinct claims. Absent metadata means not recorded, not disproved. Counting rules.