CVE-2026-8715: Vault Secrets Operator vulnerable to arbitrary file read and credential exfiltration via AppRole secretIDPath

Published Aug 13, 2026
·
Updated

Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication configuration that may allow a tenant with limited Kubernetes RBAC permissions to read files from the operator pod's filesystem and transmit their contents to a tenant-controlled endpoint, potentially leading to privilege escalation within the cluster. This vulnerability (CVE-2026-8715) is fixed in Vault Secrets Operator 1.5.0.

Affected Software

1 affected component
HashiCorp Vault Secrets Operator>=1.3.0<=1.4.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Vault Secrets Operator to a version that resolves this vulnerability.

    Fixed in 1.5.0
  2. Compensating control

    Mitigate the arbitrary file read/credential exfiltration risk by preventing tenant-controlled network access from the operator pod (e.g., restrict egress so AppRole-triggered exfiltration to tenant-controlled endpoints is blocked).

  3. Operational

    If AppRole secretIDPath/sectIDPath may have exposed operator service account credentials to a tenant, rotate/revoke any affected credentials (including the operator ServiceAccount token) after upgrading.

Event History

Aug 13, 2026
CVE Published
via MITRE·08:27 PM
Data Sourced
via MITRE·08:27 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:18 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2026-8715?

CVE-2026-8715 has a critical severity rating of 9.6.

2

How do I fix CVE-2026-8715?

To remediate CVE-2026-8715, upgrade Vault Secrets Operator to version 1.4.2 or later.

3

What systems are affected by CVE-2026-8715?

CVE-2026-8715 affects Vault Secrets Operator versions 1.3.0 to 1.4.1.

4

What type of vulnerability is CVE-2026-8715?

CVE-2026-8715 is an arbitrary file read and credential exfiltration vulnerability.

5

Can CVE-2026-8715 be exploited by users with limited permissions?

Yes, CVE-2026-8715 can be exploited by tenants with limited Kubernetes RBAC permissions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203