CVE-2026-105818
Received Received - Intake

Vault PKI ACME Server Unverified Identity Certificate Issue

Vulnerability report for CVE-2026-105818, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: HashiCorp Inc.

Description

Vault's PKI secrets engine ACME server did not restrict certificate identities that ACME challenges do not validate when issuing certificates under the default directory policy. This may allow an ACME client to obtain a certificate containing unverified identity claims, potentially enabling impersonation toward systems that trust certificates issued by the affected Vault PKI mount. This vulnerability (CVE-2026-105818) is fixed in Vault Community EditionΒ 2.1.2, and Vault Enterprise 2.1.2, 1.21.12, 1.20.17, and 1.19.23.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
HashiCorp Vault 1.14.0
HashiCorp Vault Enterprise 1.14.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-345 The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Vault's PKI secrets engine ACME server did not restrict certificate identities that ACME challenges do not validate when issuing certificates under the default directory policy. This allowed an ACME client to obtain a certificate containing unverified identity claims, potentially enabling impersonation toward systems trusting certificates from the affected Vault PKI mount.

Impact Analysis

An attacker could impersonate systems or users by obtaining certificates with unverified identities. This could lead to unauthorized access, data breaches, or man-in-the-middle attacks on systems relying on Vault-issued certificates.

Compliance Impact

This vulnerability could violate compliance requirements that mandate strict identity verification for certificates, such as GDPR's data protection principles or HIPAA's security rules for trusted communications. Unverified certificates may lead to non-compliance.

Mitigation Strategies

Upgrade Vault Community Edition to 2.1.2 or Vault Enterprise to 2.1.2, 1.21.12, 1.20.17, or 1.19.23 to address the vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105818. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart