CVE-2026-105820: Vault ACL Policy Cache Vulnerable to Cross-Namespace Policy Resolution
Vault's ACL policy cache allowed namespace traversal when policy names contained path traversal constructs. This may allow a token assigned specially crafted policy names to use the capabilities of policies defined in other namespaces, including the root namespace. This vulnerability (CVE-2026-105820) is fixed in Vault Enterprise 2.1.2, 1.21.12, 1.20.17, and 1.19.23. Vault Community Edition does not support namespaces, and is not affected.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Vault Enterpriseto a version that resolves this vulnerability.Fixed in 2.1.2 - Upgrade
Upgrade
Vault Enterpriseto a version that resolves this vulnerability.Fixed in 1.21.12 - Upgrade
Upgrade
Vault Enterpriseto a version that resolves this vulnerability.Fixed in 1.20.17 - Upgrade
Upgrade
Vault Enterpriseto a version that resolves this vulnerability.Fixed in 1.19.23
Event History
Frequently Asked Questions
Which Vault deployments are affected?
The issue affects HashiCorp Vault Enterprise deployments that use namespaces. Vault Community Edition does not support namespaces and is not affected.
What access does an attacker need to exploit this?
An attacker needs a token assigned policy names that are specially crafted with path traversal constructs. The vulnerability can then cause policy resolution across namespace boundaries, potentially including the root namespace.
What is the remediation?
Upgrade Vault Enterprise to version 2.1.2, 1.21.12, 1.20.17, or 1.19.23, where the issue is fixed.