Namespace Traversal Vulnerability in Vault by HashiCorp
CVE-2026-105820

5.4MEDIUM

Key Information:

Vendor

Hashicorp

Vendor
CVE Published:
7 October 2026

What is CVE-2026-105820?

A vulnerability in Vault's ACL policy cache allows for namespace traversal due to improperly handled policy names containing path traversal constructs. As a result, a token linked to a specially crafted policy name could potentially exploit capabilities defined in other namespaces, including the sensitive root namespace. This issue impacts specific versions of Vault Enterprise but does not affect the Vault Community Edition, which lacks namespace support.

Affected Version(s)

Vault Enterprise 64 bit 0.0.1 < 2.1.2

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was identified by an external party.
.