PT-2026-39231 · Unknown · External Secrets Operator
Factory-Kirk
+1
·
Published
2026-05-08
·
Updated
2026-05-11
·
CVE-2026-42876
CVSS v3.1
4.9
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
External Secrets Operator versions prior to 2.4.1
Description
A user with permissions to create ExternalSecret resources can cause the operator to create a Secret that Kubernetes automatically populates with a long-lived token for a specified service account. This allows the user to impersonate any service account within the namespace without requiring direct create permissions on TokenRequest or Secrets of that type.
Recommendations
Update to version 2.4.1.
Add admission control logic to prevent the use of Templates targeting undesired Types.
Remove Service Account Token generation via kube-controller-manager flags.
Restrict User RBAC on production clusters and sensitive namespaces.
Fix
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
External Secrets Operator