Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 13 Aug 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication configuration that may allow a tenant with limited Kubernetes RBAC permissions to read files from the operator pod's filesystem and transmit their contents to a tenant-controlled endpoint, potentially leading to privilege escalation within the cluster. This vulnerability (CVE-2026-8715) is fixed in Vault Secrets Operator 1.5.0. | |
| Title | Vault Secrets Operator vulnerable to arbitrary file read and credential exfiltration via AppRole secretIDPath | |
| Weaknesses | CWE-552 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: HashiCorp
Published:
Updated: 2026-08-13T20:27:39.489Z
Reserved: 2026-05-15T21:03:34.973Z
Link: CVE-2026-8715
No data.
Status : Received
Published: 2026-08-13T21:18:32.333
Modified: 2026-08-13T21:18:32.333
Link: CVE-2026-8715
No data.
OpenCVE Enrichment
Updated: 2026-08-13T22:15:03Z
-
CWE-552
Files or Directories Accessible to External Parties