Certificate Issuance Flaw in HashiCorp Vault PKI Secrets Engine
CVE-2026-105818
5.9MEDIUM
What is CVE-2026-105818?
The HashiCorp Vault's PKI secrets engine has a significant flaw in its ACME server configuration. It fails to enforce proper identity validation when issuing certificates through the default directory policy. This design oversight enables potential impersonation attacks, as an ACME client may receive certificates that contain unverified identity claims. This can undermine the trust system for any applications relying on the certificates issued from the affected Vault PKI mount. It is crucial for users to upgrade to the patched versions to mitigate risks associated with this vulnerability.
Affected Version(s)
Vault 64 bit 1.14.0 < 2.1.2
Vault Enterprise 64 bit 1.14.0 < 2.1.2