Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-34984

23
FAUCET Score

OVERVIEW CVE-2026-34984 affects External Secrets Operator (ESO) versions 2.2.0 and below. The vulnerability exists in the v2 template engine, where the getHostByName function remains accessible to user-controlled templates despite other dangerous functions being removed. This enables DNS-based exfiltration of sensitive secrets stored within Kubernetes clusters. SEVERITY The vulnerability carries a CVSS score of 6.5 (Medium) with a network-based attack vector, low complexity, and low privilege requirements. An attacker with permissions to create or update templated ExternalSecret resources can exploit this flaw. The primary impact is confidentiality loss, as secret material can be leaked through DNS queries without requiring the attacker to maintain direct outbound network access from their workload. The vulnerability does not enable modification or denial of service. EXPLOITATION STATUS Currently, there is no indication of active exploitation in the wild. The exploit is not listed on the KEV catalog and the EPSS score of 0.00034 indicates minimal community exploitation activity. However, the vulnerability is straightforward to weaponize for organizations where lower-trust users can create ExternalSecret resources and the controller has DNS resolution capabilities. The fix has been available in version 2.3.0, and affected organizations should prioritize upgrades to mitigate this risk.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.3.0CPE matchmatch criteria
cpe:2.3:a:external-secrets:external_secrets_operator:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

7.1HIGH

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
LOW
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
NONE
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.26%
Probability of exploitation in next 30 days
EPSS Percentile
17.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0026 is in the 22nd percentile among its peer group of 21,974 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

gopatch availablevia ghsa
Product: github.com/external-secrets/external-secretsFixed in: 1.3.3-0.20260331202714-6800989bdc12

Vendor Advisories (1)

goGHSA-r2pg-r6h7-crf3high

External Secrets Operator has DNS-based secret exfiltration via getHostByName in External Secrets v2 template engine

Apr 13, 2026

References

github.com / external-secrets/external-secrets/commit/6800989bdc12782ca2605d3b8bf7f2876a16551a
Patch
github.com / external-secrets/external-secrets/releases/tag/v2.3.0
ProductRelease Notes
github.com / external-secrets/external-secrets/security/advisories/GHSA-r2pg-r6h7-crf3
Vendor Advisory