CVE-2026-105818
Vault PKI ACME Issues Certificate With Unvalidated SANs
CVSS Score
5.9
EPSS Score
0.0%
EPSS Percentile
0th
Vault's PKI secrets engine ACME server did not restrict certificate identities that ACME challenges do not validate when issuing certificates under the default directory policy. This may allow an ACME client to obtain a certificate containing unverified identity claims, potentially enabling impersonation toward systems that trust certificates issued by the affected Vault PKI mount. This vulnerability (CVE-2026-105818) is fixed in Vault Community Edition 2.1.2, and Vault Enterprise 2.1.2, 1.21.12, 1.20.17, and 1.19.23.
| CWE | CWE-345 |
| Vendor | hashicorp |
| Product | vault |
| Published | Oct 7, 2026 |
Stay Ahead of the Next One
Get instant alerts for hashicorp vault
Be the first to know when new medium vulnerabilities affecting hashicorp vault are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
HashiCorp / Vault
1.14.0 < 2.1.2
HashiCorp / Vault Enterprise
1.14.0 < 2.1.2
References
Credits
This issue was identified by an external party.