CVE-2026-105820: Hashicorp Vault Enterprise
Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.
Vault's ACL policy cache allowed namespace traversal when policy names contained path traversal constructs. This may allow a token assigned specially crafted policy names to use the capabilities of policies defined in other namespaces, including the root namespace. This vulnerability (CVE-2026-105820) is fixed in Vault Enterprise 2.1.2, 1.21.12, 1.20.17, and 1.19.23. Vault Community Edition does not support namespaces, and is not affected.
Affected products
- Hashicorp Vault Enterprise: from 0.0.1, before 2.1.2 (fixed in 2.1.2)
Published 2026-10-07. Last modified 2026-10-08.