PT-2026-71871 · Hashicorp · Vault Secrets Operator
CVE-2026-8715
·
Published
2026-08-13
·
Updated
2026-09-03
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Vault Secrets Operator versions 1.3.0 through 1.4.1
Description
An arbitrary file read and credential exfiltration issue exists in the AppRole authentication configuration. This allows a tenant with limited Kubernetes RBAC (Role-Based Access Control, a method of regulating access to computer or network resources based on the roles of individual users) permissions to read files from the operator pod's filesystem and transmit the contents to a tenant-controlled endpoint, which could lead to privilege escalation within the cluster.
Recommendations
Update Vault Secrets Operator to version 1.5.0.
Exploit
Fix
LPE
Files Accessible to External Parties
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vault Secrets Operator