CVE-2026-8715
published 2026-08-13CVE-2026-8715: Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication configuration…
PriorityP357critical9.6CVSS 3.1
AVNACLPRLUINSCCHIHAN
EPSS
0.34%
27.0th percentile
Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication configuration that may allow a tenant with limited Kubernetes RBAC permissions to read files from the operator pod's filesystem and transmit their contents to a tenant-controlled endpoint, potentially leading to privilege escalation within the cluster. This vulnerability (CVE-2026-8715) is fixed in Vault Secrets Operator 1.5.0.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| hashicorp | tooling | >= 1.3.0 < 1.5.0 | 1.5.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
HashiCorp Vault Secrets Operator up to 1.4.x AppRole Authentication Configuration path traversal
vuldb·2026-08-13·CVSS 9.6
CVE-2026-8715 [CRITICAL] HashiCorp Vault Secrets Operator up to 1.4.x AppRole Authentication Configuration path traversal
A vulnerability classified as problematic was found in HashiCorp Vault Secrets Operator up to 1.4.x. Affected is an unknown function of the component AppRole Authentication Configuration. Executing a manipulation can lead to path traversal.
This vulnerability is tracked as CVE-2026-8715. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is advised.
GHSA
Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication configuration that may allow a tenant with limited Kube
ghsa_unreviewed·2026-08-13·CVSS 9.6
CVE-2026-8715 [CRITICAL] CWE-552 Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication configuration that may allow a tenant with limited Kube
Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication configuration that may allow a tenant with limited Kubernetes RBAC permissions to read files from the operator pod's filesystem and transmit their contents to a tenant-controlled endpoint, potentially leading to privilege escalation within the cluster. This vulnerability (CVE-2026-8715) is fixed in Vault Secrets Operator 1.5.0.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-8715 mingw-postgresql: PostgreSQL executes arbitrary code in restore operation [fedora-42]
bugzilla·2025-08-14·CVSS 8.8
CVE-2025-8715 [HIGH] CVE-2025-8715 mingw-postgresql: PostgreSQL executes arbitrary code in restore operation [fedora-42]
CVE-2025-8715 mingw-postgresql: PostgreSQL executes arbitrary code in restore operation [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to cl
Bugzilla
CVE-2025-8715 postgresql17: PostgreSQL executes arbitrary code in restore operation [fedora-42]
bugzilla·2025-08-14·CVSS 8.8
CVE-2025-8715 [HIGH] CVE-2025-8715 postgresql17: PostgreSQL executes arbitrary code in restore operation [fedora-42]
CVE-2025-8715 postgresql17: PostgreSQL executes arbitrary code in restore operation [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close
Bugzilla
CVE-2025-8715 postgresql16: PostgreSQL executes arbitrary code in restore operation [fedora-42]
bugzilla·2025-08-14·CVSS 8.8
CVE-2025-8715 [HIGH] CVE-2025-8715 postgresql16: PostgreSQL executes arbitrary code in restore operation [fedora-42]
CVE-2025-8715 postgresql16: PostgreSQL executes arbitrary code in restore operation [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close
2026-08-13
Published