Post

CVE-2026-105816 - Vault Vulnerable to Arbitrary Code Execution

CVE-2026-105816 - Vault Vulnerable to Arbitrary Code Execution

CVE-2026-105816 - Vault Vulnerable to Arbitrary Code Execution

Published Date: October 7, 2026
Source: Cvefeed

Vault and Vault Enterprise did not consistently verify that stored plugin catalog entries reference binaries within the configured plugin directory. When Vault uses Shamir seals and has an external plugin directory configured, a privileged operator able to restore an Integrated Storage (Raft) snapshot may be able to execute arbitrary code on the Vault host. 🚨

This vulnerability (CVE-2026-105816) is fixed in Vault Community Edition 2.1.2, and Vault Enterprise 2.1.2, 1.21.12, 1.20.17, and 1.19.23. While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2026-105816 is associated with the following CWEs: CWE-22: Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’).

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2026-105816 weaknesses. These identified attack patterns include:

  • CAPEC-64: Using Slashes and URL Encoding Combined to Bypass Validation Logic.
  • CAPEC-76: Manipulating Web Input to File System Calls.
  • CAPEC-78: Using Escaped Slashes in Alternate Encoding.
  • CAPEC-79: Using Slashes in Alternate Encoding.
  • CAPEC-126: Path Traversal.

To mitigate this vulnerability, update Vault to a fixed version to ensure plugin directory references are consistently verified. Update Vault Community Edition to 2.1.2 or later. Additionally, update Vault Enterprise to 2.1.2, 1.21.12, 1.20.17, or 1.19.23.

Read full article

This post is licensed under CC BY 4.0 by the author.