PT-2026-39231 · Unknown · External Secrets Operator

Factory-Kirk

+1

·

Published

2026-05-08

·

Updated

2026-05-11

·

CVE-2026-42876

CVSS v3.1

4.9

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions External Secrets Operator versions prior to 2.4.1
Description A user with permissions to create ExternalSecret resources can cause the operator to create a Secret that Kubernetes automatically populates with a long-lived token for a specified service account. This allows the user to impersonate any service account within the namespace without requiring direct create permissions on TokenRequest or Secrets of that type.
Recommendations Update to version 2.4.1. Add admission control logic to prevent the use of Templates targeting undesired Types. Remove Service Account Token generation via kube-controller-manager flags. Restrict User RBAC on production clusters and sensitive namespaces.

Fix

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-42876
GHSA-FQ7H-9X26-6J22

Affected Products

External Secrets Operator