CVE-2026-22822Disclosure(external-secrets / external_secrets_operator)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch external-secrets external_secrets_operator systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Starting in version 0.20.2 and prior to version 1.2.0, the `getSecretKey` template function, while introduced for senhasegura Devops Secrets Management (DSM) provider, has the ability to fetch secrets cross-namespaces with the roleBinding of the external-secrets controller, bypassing our security mechanisms. This function was completely removed in version 1.2.0, as everything done with that templating function can be done in a different way while respecting External Secrets Operator's safeguards As a workaround, use a policy engine such as Kubernetes, Kyverno, Kubewarden, or OPA to prevent the usage of `getSecretKey` in any ExternalSecret resource.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • external_secrets_operator

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Products
external_secrets_operator

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-16: 1Patch / Workaround · 2026-04-16: 1Technical Details · 2026-04-16: 104-16
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
Full discourse1 post
  • PulsePatch.io@pulsepatchio
    Disclosure

    Insecure secret retrieval (CVE-2026-22822) affects `External Secrets Operator` via `getSecretKey` templating. Review configurations, monitor for patches. #Kubernetes #CloudNative #InfoSec https://www.pulsepatch.io/posts/cve-2026-22822-external-secrets-operator-secret-retrieval

    Post summary

    The post announces CVE‑2026‑22822 affecting External Secrets Operator, explaining that the vulnerability allows insecure secret retrieval via getSecretKey templating, and urges users to review configurations and watch for vendor patches.

    0000043
    12 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appexternal-secretsexternal_secrets_operator---

Explore more