File Read Vulnerability in Vault Secrets Operator by HashiCorp
CVE-2026-8715

9.6CRITICAL

Key Information:

Vendor

Hashicorp

Status
Vendor
CVE Published:
13 August 2026

What is CVE-2026-8715?

Vault Secrets Operator versions 1.3.0 through 1.4.1 are susceptible to an issue that allows arbitrary file reading and credential exfiltration due to misconfigured AppRole authentication settings. Malicious actors with limited Kubernetes RBAC permissions can exploit this vulnerability to access sensitive files from the operator's filesystem and send the data to external endpoints under their control. This may lead to unauthorized privilege escalation within the Kubernetes cluster. The vulnerability is addressed in Vault Secrets Operator version 1.5.0.

Affected Version(s)

Tooling 64 bit 1.3.0 < 1.5.0

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was reported to HashiCorp by Trung Nguyen (@everping) of CyStack and Artem Cherezov (https://github.com/cherez0ff).
.