Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-105818— Vault PKI ACME Issues Certificate With Unvalidated SANs

Quick assessment

Affected
HashiCorp Vault
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Vault 的 PKI 秘密引擎的 ACME 服务器在根据默认目录策略签发证书时,未对 ACME 挑战未能验证的证书身份进行限制。这可能导致 ACME 客户端获取包含未经验证的身份声明的证书,从而可能使攻击者能够向信任由受影响的 Vault PKI 挂载所签发证书的系统进行冒充。此漏洞(CVE-2026-105818)已在 Vault Community Edition 2.1.2 以及 Vault Enterprise 2.1.2、1.21.12、1.20.17 和 1.19.23 版本中修复。

CVSS 5.9 · Medium

Possible ATT&CK Techniques 1 AI

T1195 · Supply Chain Compromise
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-105818

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Vault PKI ACME Issues Certificate With Unvalidated SANs
Source: CVE Program / CVE List V5
Vulnerability Description
Vault's PKI secrets engine ACME server did not restrict certificate identities that ACME challenges do not validate when issuing certificates under the default directory policy. This may allow an ACME client to obtain a certificate containing unverified identity claims, potentially enabling impersonation toward systems that trust certificates issued by the affected Vault PKI mount. This vulnerability (CVE-2026-105818) is fixed in Vault Community Edition 2.1.2, and Vault Enterprise 2.1.2, 1.21.12, 1.20.17, and 1.19.23.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
对数据真实性的验证不充分
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
HashiCorp Vault 1.14.0 ~ 2.1.2 -
HashiCorp Vault Enterprise 1.14.0 ~ 2.1.2 -

II. Public POCs for CVE-2026-105818

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-105818

请登录查看更多情报信息。

Other References for CVE-2026-105818 (1)

Same Patch Batch · HashiCorp · 2026-10-07 · 4 CVEs total

CVE-2026-105816 8.0 HIGH Vault Vulnerable to Arbitrary Code Execution via Plugin Catalog Entries Restored From Raft
CVE-2026-89322 7.2 HIGH Vault ACL Policy Evaluation May Allow Bypass of Deny Restrictions
CVE-2026-105820 5.4 MEDIUM Vault ACL Policy Cache Vulnerable to Cross-Namespace Policy Resolution

IV. Related Vulnerabilities

V. Comments for CVE-2026-105818

No comments yet


Leave a comment