CVE-2026-105816
Vault Vulnerable to Arbitrary Code Execution via Plugin Catalog Entries Restored From Raft Snapshots
CVSS Score
8.0
EPSS Score
0.0%
EPSS Percentile
0th
Vault and Vault Enterprise did not consistently verify that stored plugin catalog entries reference binaries within the configured plugin directory. When Vault uses Shamir seals and has an external plugin directory configured, a privileged operator able to restore an Integrated Storage (Raft) snapshot may be able to execute arbitrary code on the Vault host. This vulnerability (CVE-2026-105816) is fixed in Vault Community Edition 2.1.2, and Vault Enterprise 2.1.2, 1.21.12, 1.20.17, and 1.19.23.
| CWE | CWE-22 |
| Vendor | hashicorp |
| Product | vault |
| Published | Oct 7, 2026 |
Stay Ahead of the Next One
Get instant alerts for hashicorp vault
Be the first to know when new high vulnerabilities affecting hashicorp vault are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
HashiCorp / Vault
0.0.1 < 2.1.2
HashiCorp / Vault Enterprise
0.0.1 < 2.1.2
References
Credits
This issue was identified by an external party.