Incorrect Authorization Affecting external-secrets-operator package, versions <1.2.0-r0


Severity

Recommended
0.0
high
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
0.19% (10th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-MINIMOSLATEST-EXTERNALSECRETSOPERATOR-15052025
  • published22 Jan 2026
  • disclosed21 Jan 2026

Introduced: 21 Jan 2026

CVE-2026-22822  (opens in a new tab)
CWE-863  (opens in a new tab)

How to fix?

Upgrade Minimos:latest external-secrets-operator to version 1.2.0-r0 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream external-secrets-operator package and not the external-secrets-operator package as distributed by Minimos. See How to fix? for Minimos:latest relevant fixed versions and status.

External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Starting in version 0.20.2 and prior to version 1.2.0, the getSecretKey template function, while introduced for senhasegura Devops Secrets Management (DSM) provider, has the ability to fetch secrets cross-namespaces with the roleBinding of the external-secrets controller, bypassing our security mechanisms. This function was completely removed in version 1.2.0, as everything done with that templating function can be done in a different way while respecting External Secrets Operator's safeguards As a workaround, use a policy engine such as Kubernetes, Kyverno, Kubewarden, or OPA to prevent the usage of getSecretKey in any ExternalSecret resource.

CVSS Base Scores

version 3.1