Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 07 Oct 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hashicorp
Hashicorp vault Hashicorp vault Enterprise |
|
| Vendors & Products |
Hashicorp
Hashicorp vault Hashicorp vault Enterprise |
Wed, 07 Oct 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vault's PKI secrets engine ACME server did not restrict certificate identities that ACME challenges do not validate when issuing certificates under the default directory policy. This may allow an ACME client to obtain a certificate containing unverified identity claims, potentially enabling impersonation toward systems that trust certificates issued by the affected Vault PKI mount. This vulnerability (CVE-2026-105818) is fixed in Vault Community EditionĀ 2.1.2, and Vault Enterprise 2.1.2, 1.21.12, 1.20.17, and 1.19.23. | |
| Title | Vault PKI ACME Issues Certificate With Unvalidated SANs | |
| Weaknesses | CWE-345 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: HashiCorp
Published:
Updated: 2026-10-07T21:21:05.675Z
Reserved: 2026-10-05T21:29:09.727Z
Link: CVE-2026-105818
No data.
Status : Received
Published: 2026-10-07T22:17:02.843
Modified: 2026-10-07T22:17:02.843
Link: CVE-2026-105818
No data.
OpenCVE Enrichment
Updated: 2026-10-07T22:30:14Z