Vulnerability
Published 2026-10-07
Verified 2026-10-08

HashiCorp Vault 2.1.2 fixes four flaws: canonical-name ACL bypass of explicit deny rules (CVE-2026-89322, 7.2), code execution through plugin catalog entries in restored Raft snapshots (CVE-2026-105816, 8.0), unvalidated names in ACME-issued certificates and an Enterprise cross-namespace policy leak

HashiCorp published four Vault security bulletins on 7 October 2026, all fixed in Vault Community Edition 2.1.2 and Vault Enterprise 2.1.2, 1.21.12, 1.20.17 and 1.19.23. HCSEC-2026-43 (CVE-2026-89322, CVSS 3.1 7.2): Vault did not always evaluate ACL policies against the canonical form of resource and policy names, so an authenticated user with delegated permissions could get around an explicit deny, reach a protected resource or assign a denied policy, and so escalate privileges. HCSEC-2026-41 (CVE-2026-105816, 8.0): with Shamir seals and an external plugin directory configured, a privileged operator who can restore an Integrated Storage (Raft) snapshot may be able to run arbitrary code on the Vault host, because stored plugin catalog entries were not checked to point inside the plugin directory. HCSEC-2026-40 (CVE-2026-105818, 5.9): under the default directory policy, the PKI secrets engine's ACME server could issue certificates containing identities the ACME challenge never validated, which could allow impersonation toward systems that trust that PKI mount (affects 1.14.0 and later). HCSEC-2026-42 (CVE-2026-105820, 5.4, Enterprise only): crafted policy names with path traversal let a token use policies from other namespaces, including the root namespace. HashiCorp does not report exploitation. Primary: HashiCorp security bulletins and CVE records.

Product
HashiCorp Vault Community Edition and Vault Enterprise
Versions
Vault Community Edition before 2.1.2; Vault Enterprise before 2.1.2, 1.21.12, 1.20.17 and 1.19.23 (CVE-2026-105818 from 1.14.0; CVE-2026-105820 Enterprise only)
CVSS
High (CVE-2026-105816), 7.2 High (CVE-2026-89322), 5.9 (CVE-2026-105818), 5.4 (CVE-2026-105820), CVSS 3.1, HashiCorp
Exploited in Australia?
unknown
Patch to
Upgrade to Vault 2.1.2, or Vault Enterprise 2.1.2, 1.21.12, 1.20.17 or 1.19.23. Until then, review policies that rely on explicit deny rules and who can delegate policy assignment, restrict who can restore Raft snapshots and only restore snapshots from trusted sources, and check which identities an ACME-enabled PKI mount will issue under its directory policy. Review recently issued ACME certificates for unexpected names.

Primary: HashiCorp — HCSEC-2026-43: Vault inconsistent ACL policy evaluation may allow bypass of deny restrictions (7 Oct 2026) · Vendor: HashiCorp — HCSEC-2026-41: Vault arbitrary code execution via plugin catalog entries restored from Raft snapshots (7 Oct 2026) · CVE: CVE-2026-89322, CVE-2026-105816, CVE-2026-105818, CVE-2026-105820 · HashiCorp — HCSEC-2026-40: Vault PKI ACME default directory policy may issue certificates with unverified identities (7 Oct 2026)

vulnerabilities identity cloud