CVE-2026-105816: Vault Vulnerable to Arbitrary Code Execution via Plugin Catalog Entries Restored From Raft Snapshots
Vault and Vault Enterprise did not consistently verify that stored plugin catalog entries reference binaries within the configured plugin directory. When Vault uses Shamir seals and has an external plugin directory configured, a privileged operator able to restore an Integrated Storage (Raft) snapshot may be able to execute arbitrary code on the Vault host. This vulnerability (CVE-2026-105816) is fixed in Vault Community Edition 2.1.2, and Vault Enterprise 2.1.2, 1.21.12, 1.20.17, and 1.19.23.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Vault Community Editionto a version that resolves this vulnerability.Fixed in 2.1.2 - Upgrade
Upgrade
Vault Enterpriseto a version that resolves this vulnerability.Fixed in 2.1.2 - Upgrade
Upgrade
Vault Enterpriseto a version that resolves this vulnerability.Fixed in 1.21.12 - Upgrade
Upgrade
Vault Enterpriseto a version that resolves this vulnerability.Fixed in 1.20.17 - Upgrade
Upgrade
Vault Enterpriseto a version that resolves this vulnerability.Fixed in 1.19.23
Event History
Frequently Asked Questions
Which Vault deployments are exposed to this issue?
The affected scenario requires Vault to use Shamir seals and an external plugin directory. It also involves Integrated Storage (Raft) snapshots.
What access would an attacker need to exploit this?
An attacker would need privileged operator access sufficient to restore an Integrated Storage (Raft) snapshot. Exploitation can then result in arbitrary code execution on the Vault host.
Which releases include the fix?
The issue is fixed in Vault Community Edition 2.1.2 and Vault Enterprise 2.1.2, 1.21.12, 1.20.17, and 1.19.23.