Description
Vault's PKI secrets engine ACME server did not restrict certificate identities that ACME challenges do not validate when issuing certificates under the default directory policy. This may allow an ACME client to obtain a certificate containing unverified identity claims, potentially enabling impersonation toward systems that trust certificates issued by the affected Vault PKI mount. This vulnerability (CVE-2026-105818) is fixed in Vault Community Edition 2.1.2, and Vault Enterprise 2.1.2, 1.21.12, 1.20.17, and 1.19.23.
Published: 2026-10-07
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unverified certificate issuance enabling impersonation
Action: Patch
AI Analysis

Impact

Vault’s PKI secrets engine ACME server can issue certificates that include subject alternative names (SANs) that have not been validated by the ACME challenge, allowing an attacker to obtain a certificate with unverified identity claims. This flaw is classified as a weakness in untrusted input handling (CWE‑345) and could enable an attacker to impersonate other systems that trust certificates issued by the affected Vault PKI mount.

Affected Systems

The vulnerability affects HashiCorp Vault Community Edition versions earlier than 2.1.2 and Vault Enterprise version 2.1.2 and earlier, specifically Enterprise releases 1.21.12, 1.20.17, and 1.19.23. Any deployment of the PKI secrets engine that uses the default directory policy and has not been updated to a patched version is at risk.

Risk and Exploitability

The CVSS score for this issue is 5.9, indicating a moderate severity, and the EPSS score is not available. It is not listed in the CISA Known Exploited Vulnerability catalog. The likely attack vector is through a client using the ACME protocol against a Vault instance that has the default directory policy enabled; the attacker can supply an ACME challenge that does not verify the desired SANs and receive a certificate containing those unvalidated identities.

Generated by OpenCVE AI on October 7, 2026 at 22:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Vault Community Edition 2.1.2 or newer, or Vault Enterprise 1.21.12, 1.20.17, 1.19.23, or 2.1.2 and later.
  • Configure the PKI mount’s directory policy to enforce validation of SANs and remove the default directory policy that allows unverified identities.
  • Revoke any certificates that may have been issued with unverified SANs before applying the patch and reissue valid certificates under the corrected policy.

Generated by OpenCVE AI on October 7, 2026 at 22:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Hashicorp
Hashicorp vault
Hashicorp vault Enterprise
Vendors & Products Hashicorp
Hashicorp vault
Hashicorp vault Enterprise

Wed, 07 Oct 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vault's PKI secrets engine ACME server did not restrict certificate identities that ACME challenges do not validate when issuing certificates under the default directory policy. This may allow an ACME client to obtain a certificate containing unverified identity claims, potentially enabling impersonation toward systems that trust certificates issued by the affected Vault PKI mount. This vulnerability (CVE-2026-105818) is fixed in Vault Community Edition 2.1.2, and Vault Enterprise 2.1.2, 1.21.12, 1.20.17, and 1.19.23.
Title Vault PKI ACME Issues Certificate With Unvalidated SANs
Weaknesses CWE-345
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

Hashicorp Vault Vault Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: HashiCorp

Published:

Updated: 2026-10-07T21:21:05.675Z

Reserved: 2026-10-05T21:29:09.727Z

Link: CVE-2026-105818

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T22:17:02.843

Modified: 2026-10-07T22:17:02.843

Link: CVE-2026-105818

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T22:30:14Z

Weaknesses
  • CWE-345

    Insufficient Verification of Data Authenticity