Arbitrary Code Execution in HashiCorp Vault and Vault Enterprise
CVE-2026-105816

8HIGH

Key Information:

Vendor

Hashicorp

Vendor
CVE Published:
7 October 2026

What is CVE-2026-105816?

HashiCorp Vault and Vault Enterprise contain a vulnerability that may enable an attacker to execute arbitrary code on the Vault host. This security issue arises when the system fails to correctly verify that entries in the plugin catalog reference binaries that are securely located within the designated plugin directory. In scenarios where Vault utilizes Shamir seals and has an external plugin directory configured, a privileged operator with the capability to restore an Integrated Storage (Raft) snapshot could exploit this flaw. The vulnerability presents a potential risk to the integrity of the system's operations, allowing unauthorized code execution.

Affected Version(s)

Vault 64 bit 0.0.1 < 2.1.2

Vault Enterprise 64 bit 0.0.1 < 2.1.2

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was identified by an external party.
.