CVE-2026-8715 PUBLISHED

Vault Secrets Operator vulnerable to arbitrary file read and credential exfiltration via AppRole secretIDPath

Assigner: HashiCorp
Reserved: 15.05.2026 Published: 13.08.2026 Updated: 14.08.2026

Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication configuration that may allow a tenant with limited Kubernetes RBAC permissions to read files from the operator pod's filesystem and transmit their contents to a tenant-controlled endpoint, potentially leading to privilege escalation within the cluster. This vulnerability (CVE-2026-8715) is fixed in Vault Secrets Operator 1.5.0.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
CVSS Score: 9.6

Product Status

Vendor HashiCorp
Product Tooling
Versions Default: unaffected
  • affected from 1.3.0 to 1.5.0 (excl.)

Credits

  • This issue was reported to HashiCorp by Trung Nguyen (@everping) of CyStack and Artem Cherezov (https://github.com/cherez0ff).

References

Problem Types

  • CWE-552: Files or Directories Accessible to External Parties CWE

Impacts

  • CAPEC-122: Privilege Abuse