


Perceptive Security
SOC/SIEM Consultancy

vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. Prior to 1.23.1, parseVaultConfig() in pkg/webhook…
Published:
30 July 2026 at 22:00:00
Alert date:
31 July 2026 at 19:01:11
Source:
nvd.nist.gov
Cloud & Virtualization, Identity & Access
A vulnerability in vault-secrets-webhook, a Kubernetes mutating webhook for direct secret injection into Pods, allows an attacker to exfiltrate ServiceAccount JWTs. Prior to version 1.23.1, the parseVaultConfig() function in pkg/webhook/config.go accepts the vault.security.banzaicloud.io/vault-addr annotation without sufficient validation. The MutateConfigMap and MutateSecret functions call newVaultClient, which can be directed to an attacker-controlled Vault address via the vault.security.banzaicloud.io/vault-serviceaccount annotation. This allows a malicious actor to receive ServiceAccount JWTs, potentially compromising Kubernetes cluster authentication and authorization. The vulnerability affects all versions prior to 1.23.1. The fix was released in version 1.23.1 of vault-secrets-webhook by bank-vaults. Organizations using this webhook should upgrade immediately to prevent credential theft and potential cluster compromise.
Technical details
Mitigation steps:
Affected products:
vault-secrets-webhook
Kubernetes
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-54725
https://github.com/bank-vaults/vault-secrets-webhook/commit/76db45976fee0f54cafd94dffa425e6b542f65a0
https://github.com/bank-vaults/vault-secrets-webhook/releases/tag/v1.23.1
https://github.com/bank-vaults/vault-secrets-webhook/security/advisories/GHSA-r2v3-8gwf-7ghm
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
