Label enforcement bypass in webhook generator enables secret exfiltration
Upstream fixed versions: github.com/external-secrets/external-secrets: v1.3.2; v2.0.0+
CVE-2026-26287: RESERVED; not counted as a published CVE
details
- Finding IDs
- F-ESO-LABELBYPASS-001
- CVE
- CVE-2026-26287
- GHSA
- GHSA-q7hv-xx6h-q2x8
- Status
- patched
- Fixed in
- external-secrets v1.3.2; v2.0.0+
- Recorded credit
- @1seal: reporter (accepted); @evrardj-roche: reporter; @gusfcarvalho: remediation developer
- Note
- GHSA-q7hv-xx6h-q2x8 was published on 2026-10-06 and credits @1seal as a reporter. Webhook generator initialization clears EnforceLabels, allowing an authorized generator creator to reference an unlabeled same-namespace Secret for an outbound webhook. GitHub lists CVE-2026-26287, but the CVE List entry remained RESERVED at the recorded check; this advisory is counted as a published GHSA, not a published CVE, until that state changes.
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
- CVE registry state
- RESERVED
- CVE state checked
- CVSS assessment
- external-secrets GitHub advisory; v3.1; 7.1; observed 2026-10-06
- Upstream title
- Label enforcement bypass in webhook generator enables secret exfiltration
- Upstream publication
- Upstream updated
- Metadata fetched
- Upstream fixed versions
- github.com/external-secrets/external-secrets: v1.3.2; v2.0.0+
- Upstream affected ranges
- github.com/external-secrets/external-secrets: v0.10.0–v1.3.1
- Upstream @1seal credit
- @1seal: reporter (accepted)
F-ESO-LABELBYPASS-001: Access control. The recorded webhook initialization-order fix concerns bypassing the intended validation policy. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-ESO-LABELBYPASS-001
Security area (1seal assessment): Authorization. Webhook generator initialization bypasses the intended secret-label authorization gate. Reviewed 6 Oct 2026.