What is CVE-2026-54725?
CVE-2026-54725 affects the vault-secrets-webhook, a Kubernetes mutating webhook for direct secret injection. The vulnerability exists in versions prior to 1.23.1 due to improper handling of the `vault-addr` annotation. Users are advised to upgrade to version 1.23.1 or later immediately.
Azərbaycanca: CVE-2026-54725, Kubernetes mutating webhook kimi fəaliyyət göstərən vault-secrets-webhook komponentində aşkarlanıb. 1.23.1 versiyasından əvvəlki versiyalarda `vault-addr` annotasiyasının düzgün yoxlanılmaması potensial təhlükəsizlik riski yaradır. İstifadəçilərə bu zəiflikdən qorunmaq üçün dərhal 1.23.1 və ya daha yuxarı versiyaya yeniləmə tövsiyə olunur.
FAQ2
Which component does CVE-2026-54725 affect?
This vulnerability affects the vault-secrets-webhook component, which acts as a Kubernetes mutating webhook.
Which version is recommended to update to in order to mitigate CVE-2026-54725?
It is recommended to immediately upgrade vault-secrets-webhook to version 1.23.1 or later to mitigate this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.