CVE-2026-22822
External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Starting in version 0.20.2 and prior to version 1.2.0, the `getSecretKey` template function, while introduced for senhasegura Devops Secrets Management (DSM) provider, has the ability to fetch secrets cross-namespaces with the roleBinding of the external-secrets controller, bypassing our security mechanisms.
Leer descripción completaMostrar menos
This function was completely removed in version 1.2.0, as everything done with that templating function can be done in a different way while respecting External Secrets Operator's safeguards As a workaround, use a policy engine such as Kubernetes, Kyverno, Kubewarden, or OPA to prevent the usage of `getSecretKey` in any ExternalSecret resource.
CVSS
- Versión: 4.0
- Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Puntuación base: 9.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.19%
- Percentil entre todas las CVEs puntuadas: 8
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1068Exploitation for Privilege Escalationprivilege escalation95 % - Impacto principal
T1078Valid Accountsstealth · persistence · privilege escalation · initial access90 % - Impacto secundario
T1005Data from Local Systemcollection85 %
Acceso local con privilegios (AV:L, PR:L) permite escalada mediante función getSecretKey para leer secretos entre espacios de nombres, bypassing RBAC controls.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-863
- CWE-863
Referencias
- https://github.com/external-secrets/external-secrets/commit/17d3e22b8d3fbe339faf8515a95ec06ec92b1feb
- https://github.com/external-secrets/external-secrets/issues/5690
- https://github.com/external-secrets/external-secrets/pull/3895
- https://github.com/external-secrets/external-secrets/releases/tag/v1.2.0
- https://github.com/external-secrets/external-secrets/security/advisories/GHSA-77v3-r3jw-j2v2
- https://access.redhat.com/security/cve/CVE-2026-22822
- https://bugzilla.redhat.com/show_bug.cgi?id=2431873
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-22822.json
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-22822",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-22822",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2026-01-22T15:10:57.677512Z"
}
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 6,
"exploitabilityScore": 2
},
{
"type": "Secondary",
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 6,
"exploitabilityScore": 2
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "NOT_DEFINED",
"baseScore": 9.3,
"Automatable": "NOT_DEFINED",
"attackVector": "LOCAL",
"baseSeverity": "CRITICAL",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"exploitMaturity": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"privilegesRequired": "LOW",
"subIntegrityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "HIGH",
"vulnAvailabilityImpact": "HIGH",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "external-secrets",
"product": "external-secrets",
"versions": [
{
"status": "affected",
"version": ">= 0.20.2, < 1.2.0"
}
]
}
]
},
{
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
"affectedData": [
{
"cpes": [
"cpe:/a:redhat:external_secrets_operator:1"
],
"vendor": "Red Hat",
"product": "External Secrets Operator for Red Hat OpenShift",
"packageName": "external-secrets-operator/bitwarden-sdk-server-rhel9",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "unaffected"
},
{
"cpes": [
"cpe:/a:redhat:external_secrets_operator:1"
],
"vendor": "Red Hat",
"product": "External Secrets Operator for Red Hat OpenShift",
"packageName": "external-secrets-operator/external-secrets-operator-bundle",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "unaffected"
},
{
"cpes": [
"cpe:/a:redhat:external_secrets_operator:1"
],
"vendor": "Red Hat",
"product": "External Secrets Operator for Red Hat OpenShift",
"packageName": "external-secrets-operator/external-secrets-operator-rhel9",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "unaffected"
},
{
"cpes": [
"cpe:/a:redhat:external_secrets_operator:1"
],
"vendor": "Red Hat",
"product": "External Secrets Operator for Red Hat OpenShift",
"packageName": "external-secrets-operator/external-secrets-rhel9",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "unaffected"
},
{
"cpes": [
"cpe:/a:redhat:external_secrets_operator:0"
],
"vendor": "Red Hat",
"product": "external secrets operator for Red Hat OpenShift - Tech Preview",
"packageName": "external-secrets-operator/bitwarden-sdk-server-rhel9",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:external_secrets_operator:0"
],
"vendor": "Red Hat",
"product": "external secrets operator for Red Hat OpenShift - Tech Preview",
"packageName": "external-secrets-operator/external-secrets-operator-bundle",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:external_secrets_operator:0"
],
"vendor": "Red Hat",
"product": "external secrets operator for Red Hat OpenShift - Tech Preview",
"packageName": "external-secrets-operator/external-secrets-operator-rhel9",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:external_secrets_operator:0"
],
"vendor": "Red Hat",
"product": "external secrets operator for Red Hat OpenShift - Tech Preview",
"packageName": "external-secrets-operator/external-secrets-rhel9",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
}
]
}
],
"published": "2026-01-21T22:15:49.380",
"references": [
{
"url": "https://github.com/external-secrets/external-secrets/commit/17d3e22b8d3fbe339faf8515a95ec06ec92b1feb",
"tags": [
"Patch"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/external-secrets/external-secrets/issues/5690",
"tags": [
"Issue Tracking"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/external-secrets/external-secrets/pull/3895",
"tags": [
"Issue Tracking"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/external-secrets/external-secrets/releases/tag/v1.2.0",
"tags": [
"Product",
"Release Notes"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/external-secrets/external-secrets/security/advisories/GHSA-77v3-r3jw-j2v2",
"tags": [
"Vendor Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://access.redhat.com/security/cve/CVE-2026-22822",
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431873",
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
},
{
"url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-22822.json",
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-863"
}
]
},
{
"type": "Secondary",
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
"description": [
{
"lang": "en",
"value": "CWE-863"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Starting in version 0.20.2 and prior to version 1.2.0, the `getSecretKey` template function, while introduced for senhasegura Devops Secrets Management (DSM) provider, has the ability to fetch secrets cross-namespaces with the roleBinding of the external-secrets controller, bypassing our security mechanisms. This function was completely removed in version 1.2.0, as everything done with that templating function can be done in a different way while respecting External Secrets Operator's safeguards As a workaround, use a policy engine such as Kubernetes, Kyverno, Kubewarden, or OPA to prevent the usage of `getSecretKey` in any ExternalSecret resource."
},
{
"lang": "es",
"value": "External Secrets Operator lee información de un servicio de terceros e inyecta automáticamente los valores como Secrets de Kubernetes. A partir de la versión 0.20.2 y antes de la versión 1.2.0, la función de plantilla 'getSecretKey', aunque introducida para el proveedor senhasegura Devops Secrets Management (DSM), tiene la capacidad de obtener secretos entre espacios de nombres con el roleBinding del controlador external-secrets, eludiendo nuestros mecanismos de seguridad. Esta función fue completamente eliminada en la versión 1.2.0, ya que todo lo que se hacía con esa función de plantilla se puede hacer de una manera diferente respetando las salvaguardas de External Secrets Operator. Como solución alternativa, utilice un motor de políticas como Kubernetes, Kyverno, Kubewarden u OPA para evitar el uso de 'getSecretKey' en cualquier recurso ExternalSecret."
}
],
"lastModified": "2026-07-15T02:18:37.703",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:external-secrets:external_secrets_operator:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F9E0E951-2317-45FB-A1AD-7426EFBBA6E3",
"versionEndExcluding": "1.2.0",
"versionStartIncluding": "0.20.2"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security-advisories@github.com"
}