logo

CVE-2026-22822: Critical Flaw in External Secrets Operator Breaks Namespace Isolation

ID: 33b0ebc8-3c26-5005-92cb-78e27ee5fd39

STIX ID: report--33b0ebc8-3c26-5005-92cb-78e27ee5fd39

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-01-23

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical CVE-2026-22822 vulnerability in the External Secrets Operator (CVSS 9.3) allows the getSecretKey templating function to fetch secrets across namespaces, potentially enabling privilege escalation, data exfiltration, and compromise of service accounts; maintainers removed the function and users should upgrade to v1.2.0 or apply policy-based mitigations (Kyverno/Kubewarden/OPA) until patched.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.