PT-2026-71871 · Hashicorp · Vault Secrets Operator

CVE-2026-8715

·

Published

2026-08-13

·

Updated

2026-09-03

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Vault Secrets Operator versions 1.3.0 through 1.4.1
Description An arbitrary file read and credential exfiltration issue exists in the AppRole authentication configuration. This allows a tenant with limited Kubernetes RBAC (Role-Based Access Control, a method of regulating access to computer or network resources based on the roles of individual users) permissions to read files from the operator pod's filesystem and transmit the contents to a tenant-controlled endpoint, which could lead to privilege escalation within the cluster.
Recommendations Update Vault Secrets Operator to version 1.5.0.

Exploit

Fix

LPE

Files Accessible to External Parties

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-CONSUL-2026-8715
CVE-2026-8715

Affected Products

Vault Secrets Operator