Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 14 Aug 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 14 Aug 2026 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hashicorp
Hashicorp tooling |
|
| Vendors & Products |
Hashicorp
Hashicorp tooling |
Thu, 13 Aug 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication configuration that may allow a tenant with limited Kubernetes RBAC permissions to read files from the operator pod's filesystem and transmit their contents to a tenant-controlled endpoint, potentially leading to privilege escalation within the cluster. This vulnerability (CVE-2026-8715) is fixed in Vault Secrets Operator 1.5.0. | |
| Title | Vault Secrets Operator vulnerable to arbitrary file read and credential exfiltration via AppRole secretIDPath | |
| Weaknesses | CWE-552 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: HashiCorp
Published:
Updated: 2026-08-14T12:38:35.051Z
Reserved: 2026-05-15T21:03:34.973Z
Link: CVE-2026-8715
Updated: 2026-08-14T12:38:30.425Z
Status : Received
Published: 2026-08-13T21:18:32.333
Modified: 2026-08-14T13:19:11.077
Link: CVE-2026-8715
No data.
OpenCVE Enrichment
Updated: 2026-08-14T02:45:03Z