CVE-2026-8715
Received Received - Intake

Arbitrary File Read and Credential Exfiltration in Vault Secrets Operator

Vulnerability report for CVE-2026-8715, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-13

Last updated on: 2026-08-13

Assigner: HashiCorp Inc.

Description

Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication configuration that may allow a tenant with limited Kubernetes RBAC permissions to read files from the operator pod's filesystem and transmit their contents to a tenant-controlled endpoint, potentially leading to privilege escalation within the cluster. This vulnerability (CVE-2026-8715) is fixed in Vault Secrets Operator 1.5.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-13
Last Modified
2026-08-13
Generated
2026-08-14
AI Q&A
2026-08-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
hashicorp vault_secrets_operator to 1.4.1 (inc)
hashicorp vault_secrets_operator 1.5.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-552 The product makes files or directories accessible to unauthorized actors, even though they should not be.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Vault Secrets Operator versions 1.3.0 to 1.4.1 have a flaw where a user with limited Kubernetes permissions can read files from the operator pod's filesystem and send them to an external server. This happens through the AppRole authentication setup and could allow privilege escalation within the cluster.

Impact Analysis

If exploited, an attacker with minimal access could steal sensitive data from the operator pod, such as credentials or configuration files, and use this information to gain higher privileges in the Kubernetes cluster.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, potentially violating GDPR (data protection) or HIPAA (health information privacy) by exposing confidential information stored in the operator pod.

Mitigation Strategies

Upgrade Vault Secrets Operator to version 1.5.0 or later to address the vulnerability. Review and restrict Kubernetes RBAC permissions for tenants to minimize exposure.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-8715. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart