CVE-2026-22822 | external-secrets up to 1.1.x getSecretKey authorization (ID 5690 / EUVD-2026-3404)
A vulnerability, which was classified as problematic, has been found in external-secrets up to 1.1.x. Affected is the function getSecretKey. Performing a manipulation results in incorrect authorization.
This vulnerability is identified as CVE-2026-22822. The attack is only possible with local access. There is not any exploit available.
It is advisable to upgrade the affected component.