Vault 与 Vault Enterprise 未始终验证已存储的插件目录条目是否引用了配置插件目录中的二进制文件。当 Vault 使用 Shamir 密钥分片(Shamir seals)且配置了外部插件目录时,拥有特权的操作员若能够恢复集成存储(Raft)的快照,则可能在 Vault 主机上执行任意代码。该漏洞(CVE-2026-105816)已在以下版本中修复:Vault Community Edition 2.1.2,以及 Vault Enterprise 2.1.2、1.21.12、1.20.17 和 1
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| HashiCorp | Vault | 0.0.1 ~ 2.1.2 | - |
|
| HashiCorp | Vault Enterprise | 0.0.1 ~ 2.1.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-89322 | 7.2 HIGH | Vault ACL Policy Evaluation May Allow Bypass of Deny Restrictions |
| CVE-2026-105818 | 5.9 MEDIUM | Vault PKI ACME Issues Certificate With Unvalidated SANs |
| CVE-2026-105820 | 5.4 MEDIUM | Vault ACL Policy Cache Vulnerable to Cross-Namespace Policy Resolution |
No comments yet