Vulnerability GHSA-wv26-88m5-6h59

Medium Risk
MEDIUM RISK
CVSS Score: 6.0
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
5 months ago
May 05, 2026 at 06:37 PM UTC
External Secrets Operator has Namespace Isolation Bypass in CAProvider ConfigMap Resolution for SecretStore
v0.1.0-esoctl - v1.3.2
v0.1.0-esoctl - v1.3.2

Summary

External Secrets Operator has Namespace Isolation Bypass in CAProvider ConfigMap Resolution for SecretStore

Details

Impact

Namespaced SecretStore resources that used CAProvider with type ConfigMap could resolve CA material from another namespace when caProvider.namespace was set. This bypassed the namespace boundary enforced for SecretStore-backed references in providers that rely on the shared runtime CA resolver.

The accessible data is used as CA validation material, hence it is not directly exposed.

Impact:

  • Direct data exfiltration risk: low
  • Existence disclosure: an attacker can infer whether a target ConfigMap/key exists in another namespace.
  • Trust-boundary violation: a tenant can make its SecretStore consume CA material owned by another namespace.

Timeline

Published
5 months ago
May 05, 2026 at 06:37 PM UTC
Last Modified
26 days ago
September 10, 2026 at 03:50 AM UTC