https://seclists.org/oss-sec/2026/q3/606: [CVE-2026-8715] HashiCorp Vault Sects Operator 1.3.0-1.4.1: tenant-controlled sectIDPath leaks operator ServiceAccount token (path to cluster-admin)
Published Aug 28, 2026
·Updated
Affected Software
1 affected component
HashiCorp Vault Secrets Operator (VSO)>=1.3.0<1.4.1
Frequently Asked Questions
1
Who can exploit this issue?
A tenant able to write the namespaced VaultAuth or VaultAuthGlobal resources can set secretIDPath and direct the Vault connection address to a listener they control. The operator then reads its own projected ServiceAccount token and sends it in the AppRole login request.
2
What access does a stolen operator ServiceAccount token provide?
The leaked token can read and write Secrets in every namespace. It also has cluster-wide permission to create serviceaccounts/token resources, providing a path to cluster-admin access.
3
Which releases require remediation?
HashiCorp Vault Secrets Operator versions 1.3.0 through 1.4.1 are affected. Version 1.5.0 is identified as the fixed release.