Description
Vault's ACL policy cache allowed namespace traversal when policy names contained path traversal constructs. This may allow a token assigned specially crafted policy names to use the capabilities of policies defined in other namespaces, including the root namespace. This vulnerability (CVE-2026-105820) is fixed in Vault Enterprise 2.1.2, 1.21.12, 1.20.17, and 1.19.23. Vault Community Edition does not support namespaces, and is not affected.
Published: 2026-10-07
Score: 5.4 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized Privilege Escalation via Cross‑Namespace Policy Resolution
Action: Patch
AI Analysis

Impact

Vault’s ACL policy cache incorrectly handles policy names that contain path traversal characters, allowing a token to reference policies defined in other namespaces, including the root namespace. This flaw effectively lets an attacker gain the permissions of a target namespace by supplying a crafted policy name when creating or assigning tokens, constituting an unauthorized privilege escalation. The weakness is a classic Path Traversal error (CWE‑22).

Affected Systems

The issue affects HashiCorp Vault Enterprise deployments but does not impact the Community Edition, which has no namespace support. The vulnerability is fixed in Vault Enterprise releases 2.1.2, 1.21.12, 1.20.17, and 1.19.23; older releases remain vulnerable.

Risk and Exploitability

The CVSS score is 5.4, indicating a moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation. The most likely attack vector is an internal or compromised user with the capability to create or modify tokens, who can embed path traversal patterns in policy names to hijack access across namespaces.

Generated by OpenCVE AI on October 7, 2026 at 23:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Vault Enterprise to one of the patched releases: 2.1.2, 1.21.12, 1.20.17, or 1.19.23.
  • Enforce a policy name validation rule that prohibits '.' or '/' characters so that no path traversal patterns can be used when creating or assigning policies.
  • Audit existing tokens in all namespaces to identify any that reference policy names containing '..' or '/' characters and remove or replace those tokens with safe names.

Generated by OpenCVE AI on October 7, 2026 at 23:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Hashicorp
Hashicorp vault Enterprise
Vendors & Products Hashicorp
Hashicorp vault Enterprise

Wed, 07 Oct 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vault's ACL policy cache allowed namespace traversal when policy names contained path traversal constructs. This may allow a token assigned specially crafted policy names to use the capabilities of policies defined in other namespaces, including the root namespace. This vulnerability (CVE-2026-105820) is fixed in Vault Enterprise 2.1.2, 1.21.12, 1.20.17, and 1.19.23. Vault Community Edition does not support namespaces, and is not affected.
Title Vault ACL Policy Cache Vulnerable to Cross-Namespace Policy Resolution
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Hashicorp Vault Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: HashiCorp

Published:

Updated: 2026-10-07T21:48:08.017Z

Reserved: 2026-10-05T21:35:14.384Z

Link: CVE-2026-105820

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T22:17:02.990

Modified: 2026-10-07T22:17:02.990

Link: CVE-2026-105820

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T23:30:07Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')