top of page
perceptive_background_267k.jpg

vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. Prior to 1.23.1, parseVaultConfig() in pkg/webhook…

Published:

30 July 2026 at 22:00:00

Alert date:

31 July 2026 at 19:01:11

Source:

nvd.nist.gov

Click to open the original link from this advisory

Cloud & Virtualization, Identity & Access

A vulnerability in vault-secrets-webhook, a Kubernetes mutating webhook for direct secret injection into Pods, allows an attacker to exfiltrate ServiceAccount JWTs. Prior to version 1.23.1, the parseVaultConfig() function in pkg/webhook/config.go accepts the vault.security.banzaicloud.io/vault-addr annotation without sufficient validation. The MutateConfigMap and MutateSecret functions call newVaultClient, which can be directed to an attacker-controlled Vault address via the vault.security.banzaicloud.io/vault-serviceaccount annotation. This allows a malicious actor to receive ServiceAccount JWTs, potentially compromising Kubernetes cluster authentication and authorization. The vulnerability affects all versions prior to 1.23.1. The fix was released in version 1.23.1 of vault-secrets-webhook by bank-vaults. Organizations using this webhook should upgrade immediately to prevent credential theft and potential cluster compromise.

Technical details

Mitigation steps:

Affected products:

vault-secrets-webhook
Kubernetes

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page