๐Ÿ” CVE Alert

CVE-2026-105816

HIGH 8.0

Vault Vulnerable to Arbitrary Code Execution via Plugin Catalog Entries Restored From Raft Snapshots

CVSS Score
8.0
EPSS Score
0.0%
EPSS Percentile
0th

Vault and Vault Enterprise did not consistently verify that stored plugin catalog entries reference binaries within the configured plugin directory. When Vault uses Shamir seals and has an external plugin directory configured, a privileged operator able to restore an Integrated Storage (Raft) snapshot may be able to execute arbitrary code on the Vault host. This vulnerability (CVE-2026-105816) is fixed in Vault Community Edition 2.1.2, and Vault Enterprise 2.1.2, 1.21.12, 1.20.17, and 1.19.23.

CWE CWE-22
Vendor hashicorp
Product vault
Published Oct 7, 2026
Stay Ahead of the Next One

Get instant alerts for hashicorp vault

Be the first to know when new high vulnerabilities affecting hashicorp vault are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

HashiCorp / Vault
0.0.1 < 2.1.2
HashiCorp / Vault Enterprise
0.0.1 < 2.1.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
discuss.hashicorp.com: https://discuss.hashicorp.com/t/hcsec-2026-41-vault-vulnerable-to-arbitrary-code-execution-via-plugin-catalog-entries-restored-from-raft-snapshots/77813

Credits

This issue was identified by an external party.