Arbitrary Code Execution in HashiCorp Vault and Vault Enterprise
CVE-2026-105816
8HIGH
What is CVE-2026-105816?
HashiCorp Vault and Vault Enterprise contain a vulnerability that may enable an attacker to execute arbitrary code on the Vault host. This security issue arises when the system fails to correctly verify that entries in the plugin catalog reference binaries that are securely located within the designated plugin directory. In scenarios where Vault utilizes Shamir seals and has an external plugin directory configured, a privileged operator with the capability to restore an Integrated Storage (Raft) snapshot could exploit this flaw. The vulnerability presents a potential risk to the integrity of the system's operations, allowing unauthorized code execution.
Affected Version(s)
Vault 64 bit 0.0.1 < 2.1.2
Vault Enterprise 64 bit 0.0.1 < 2.1.2