Namespace Traversal Vulnerability in Vault by HashiCorp
CVE-2026-105820
5.4MEDIUM
What is CVE-2026-105820?
A vulnerability in Vault's ACL policy cache allows for namespace traversal due to improperly handled policy names containing path traversal constructs. As a result, a token linked to a specially crafted policy name could potentially exploit capabilities defined in other namespaces, including the sensitive root namespace. This issue impacts specific versions of Vault Enterprise but does not affect the Vault Community Edition, which lacks namespace support.
Affected Version(s)
Vault Enterprise 64 bit 0.0.1 < 2.1.2