External Secrets is a Kubernetes-native operator that manages secret injection from external systems into cluster workloads, and its vulnerability surface reflects the security-sensitive nature of secrets management and external system integration. Observed disclosures have centered on the operator component itself, with attention warranted on this project given its role in credential and sensitive-data handling across containerized environments. Current vulnerability counts, severity distribution, and exploitation status are shown alongside this summary.
The number and severity of CVEs published that impact products developed by External Secrets over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-22822HIGH External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Starting in version 0.20.2 and prior to version | Jan 21, 2026 | 8.8 | 33 | NO | NO |
CVE-2024-36540CRITICAL Insecure permissions in external-secrets v0.9.16 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token. | Jul 24, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-45041HIGH External Secrets Operator is a Kubernetes operator that integrates external secret management systems. The external-secrets has a deployment called default-external-secrets-cert-co | Sep 9, 2024 | 8.8 | 25 | NO | NO |
CVE-2026-34984MEDIUM External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Versions 2.2.0 and below contain a vulnerability | Apr 14, 2026 | 6.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by External Secrets.
Media articles that mention a CVE ID that affects a product developed by External Secrets — matched by CVE ID, not by vendor name.