{"id":"CVE-2026-42875","aliases":["GHSA-wv26-88m5-6h59","GO-2026-5723"],"url":"https://o3.security/vulnerability/CVE-2026-42875","summary":"External Secrets Operator: Namespace Isolation Bypass in CAProvider ConfigMap Resolution for SecretStore","details":"### Impact\n\nNamespaced SecretStore resources that used CAProvider with type `ConfigMap` could resolve CA material from another namespace when `caProvider.namespace` was set. \nThis bypassed the namespace boundary enforced for SecretStore-backed references in providers that rely on the shared runtime CA resolver. \n\nThe accessible data is used as CA validation material, hence it is not directly exposed.\n\nImpact:\n- Direct data exfiltration risk: low\n- Existence disclosure: an attacker can infer whether a target ConfigMap/key exists in another namespace.\n- Trust-boundary violation: a tenant can make its SecretStore consume CA material owned by another namespace.","published":"2026-05-11T18:56:34.097Z","modified":"2026-08-12T03:51:12.989292947Z","cvss":null,"epss":{"score":0.0024,"percentile":0.15245,"asOf":"2026-08-14"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/external-secrets/external-secrets","fixedVersion":"2.4.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/42xxx/CVE-2026-42875.json"},{"type":"ADVISORY","url":"https://github.com/external-secrets/external-secrets/security/advisories/GHSA-wv26-88m5-6h59"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42875"},{"type":"PACKAGE","url":"https://github.com/external-secrets/external-secrets"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:12.989292947Z"}}