Vault 的 PKI 秘密引擎的 ACME 服务器在根据默认目录策略签发证书时,未对 ACME 挑战未能验证的证书身份进行限制。这可能导致 ACME 客户端获取包含未经验证的身份声明的证书,从而可能使攻击者能够向信任由受影响的 Vault PKI 挂载所签发证书的系统进行冒充。此漏洞(CVE-2026-105818)已在 Vault Community Edition 2.1.2 以及 Vault Enterprise 2.1.2、1.21.12、1.20.17 和 1.19.23 版本中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| HashiCorp | Vault | 1.14.0 ~ 2.1.2 | - |
|
| HashiCorp | Vault Enterprise | 1.14.0 ~ 2.1.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105816 | 8.0 HIGH | Vault Vulnerable to Arbitrary Code Execution via Plugin Catalog Entries Restored From Raft |
| CVE-2026-89322 | 7.2 HIGH | Vault ACL Policy Evaluation May Allow Bypass of Deny Restrictions |
| CVE-2026-105820 | 5.4 MEDIUM | Vault ACL Policy Cache Vulnerable to Cross-Namespace Policy Resolution |
No comments yet