Skip to content
HashiCorpCVE-2026-8715

HashiCorp Tooling: arbitrary file read

Critical9.6CVE-2026-8715 · Published Aug 13, 2026 · updated Aug 28, 2026

Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication configuration that may allow a tenant with limited Kubernetes RBAC permissions to read files from the operator pod's filesystem and transmit their contents to a tenant-controlled endpoint, potentially leading to privilege escalation within the cluster. This vulnerability (CVE-2026-8715) is fixed in Vault Secrets Operator 1.5.0.

HashiCorp advisory

Affected versions

PackageAffectedFixed in
Tooling
Product
>= 1.3.0, < 1.5.01.5.0
Details and references

More HashiCorp advisories

All HashiCorp
Advisory
HashiCorp Packer: code execution
High7.1Aug 17
HashiCorp Vault Enterprise: missing authorization
High8.2Aug 10
HashiCorp Vault: improper authorization
Medium4.3Aug 10
HashiCorp Consul: denial of service
High7.5Aug 7
HashiCorp Consul: denial of service
Medium5.3Aug 7
HashiCorp Consul: resource exhaustion
Medium4.3Aug 7

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.