Incorrect Authorization Affecting github.com/external-secrets/external-secrets/apis/externalsecrets/v1 package, versions <2.4.1


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.22% (12th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Incorrect Authorization vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-GOLANG-GITHUBCOMEXTERNALSECRETSEXTERNALSECRETSAPISEXTERNALSECRETSV1-16643462
  • published14 May 2026
  • disclosed8 May 2026
  • creditfactory-nizar, Kirk Strauser

Introduced: 8 May 2026

CVE-2026-42876  (opens in a new tab)
CWE-863  (opens in a new tab)

How to fix?

Upgrade github.com/external-secrets/external-secrets/apis/externalsecrets/v1 to version 2.4.1 or higher.

Overview

Affected versions of this package are vulnerable to Incorrect Authorization via ExternalSecret resource handling for Service Account tokens. A user can impersonate service accounts by crafting ExternalSecret resources that cause the operator to create Secrets populated with long-lived tokens for arbitrary service accounts in the namespace, bypassing intended permission boundaries.

Note This can only be exploited if additional misconfigurations are present in the ESO installation, as the attacker cannot gain access to further information using this method alone. The privileges gained by exploiting this are only marginally greater than those the attacker must have as a prerequisite.

Workaround

This vulnerability can be mitigated by adding admission control logic to prevent the use of Templates targeting undesired Types, removing Service Account Token generation via kube-controller-manager flags, or restricting User RBAC on production clusters and sensitive namespaces.

CVSS Base Scores

version 4.0
version 3.1