Certificate Issuance Flaw in HashiCorp Vault PKI Secrets Engine
CVE-2026-105818

5.9MEDIUM

Key Information:

Vendor

Hashicorp

Vendor
CVE Published:
7 October 2026

What is CVE-2026-105818?

The HashiCorp Vault's PKI secrets engine has a significant flaw in its ACME server configuration. It fails to enforce proper identity validation when issuing certificates through the default directory policy. This design oversight enables potential impersonation attacks, as an ACME client may receive certificates that contain unverified identity claims. This can undermine the trust system for any applications relying on the certificates issued from the affected Vault PKI mount. It is crucial for users to upgrade to the patched versions to mitigate risks associated with this vulnerability.

Affected Version(s)

Vault 64 bit 1.14.0 < 2.1.2

Vault Enterprise 64 bit 1.14.0 < 2.1.2

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was identified by an external party.
.