CVE-2026-8715: Vault Secrets Operator vulnerable to arbitrary file read and credential exfiltration via AppRole secretIDPath
Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication configuration that may allow a tenant with limited Kubernetes RBAC permissions to read files from the operator pod's filesystem and transmit their contents to a tenant-controlled endpoint, potentially leading to privilege escalation within the cluster. This vulnerability (CVE-2026-8715) is fixed in Vault Secrets Operator 1.5.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Vault Secrets Operatorto a version that resolves this vulnerability.Fixed in 1.5.0 - Compensating control
Restrict access to the Vault Secrets Operator AppRole authentication configuration and limit tenants’ Kubernetes RBAC permissions so they cannot read files from the operator pod filesystem and exfiltrate credentials to a tenant-controlled endpoint (related to arbitrary file read and credential exfiltration via AppRole secretIDPath).