Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-105820— Vault ACL Policy Cache Vulnerable to Cross-Namespace Policy Resolution

Quick assessment

Affected
HashiCorp Vault Enterprise
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Vault 的 ACL 策略缓存中存在名称空间遍历漏洞,当策略名称包含路径遍历构造时即可触发此问题。该漏洞可能导致被分配了特制策略名称的令牌,能够使用其他名称空间(包括根名称空间)中定义的策略的能力。此漏洞(CVE-2026-105820)已在以下版本中修复:Vault Enterprise 2.1.2、1.21.12、1.20.17 和 1.19.23。Vault 社区版不支持名称空间,因此不受此漏洞影响。

CVSS 5.4 · Medium

Possible ATT&CK Techniques 1 AI

T1078.004 · Cloud Accounts
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-105820

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Vault ACL Policy Cache Vulnerable to Cross-Namespace Policy Resolution
Source: CVE Program / CVE List V5
Vulnerability Description
Vault's ACL policy cache allowed namespace traversal when policy names contained path traversal constructs. This may allow a token assigned specially crafted policy names to use the capabilities of policies defined in other namespaces, including the root namespace. This vulnerability (CVE-2026-105820) is fixed in Vault Enterprise 2.1.2, 1.21.12, 1.20.17, and 1.19.23. Vault Community Edition does not support namespaces, and is not affected.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
HashiCorp Vault Enterprise 0.0.1 ~ 2.1.2 -

II. Public POCs for CVE-2026-105820

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-105820

请登录查看更多情报信息。

Other References for CVE-2026-105820 (1)

Same Patch Batch · HashiCorp · 2026-10-07 · 4 CVEs total

CVE-2026-105816 8.0 HIGH Vault Vulnerable to Arbitrary Code Execution via Plugin Catalog Entries Restored From Raft
CVE-2026-89322 7.2 HIGH Vault ACL Policy Evaluation May Allow Bypass of Deny Restrictions
CVE-2026-105818 5.9 MEDIUM Vault PKI ACME Issues Certificate With Unvalidated SANs

IV. Related Vulnerabilities

V. Comments for CVE-2026-105820

No comments yet


Leave a comment