VendorsExternal Secretsexternal_secrets_operatorall versions
Vulnerabilities

External Secrets Operator

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2024-36540
Insecure permissions in external-secrets v0.9.16 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.
Published 2024-07-24 · Analyzed
9.8EPSS 0.004
CVE-2026-22822
External Secrets Operator insecurely retrieves secrets through the getSecretKey templating function
Published 2026-01-21 · Modified
9.3EPSS 0.002
CVE-2024-45041
External Secrets Operator vulnerable to privilege escalation
Published 2024-09-09 · Analyzed
8.8EPSS 0.006
CVE-2026-34984
External Secrets Operator has DNS exfiltration via getHostByName in its v2 template engine
Published 2026-04-14 · Analyzed
7.1EPSS 0.004