CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

HashiCorp security advisory (AV26-817)

unknown
Serial number: AV26-817 Date: August 14, 2026 As of August 13, 2026, HashiCorp is affected by a vulnerability in the following product Vault Secrets Operator - Prior to 1.5.0 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. HCSEC-2026-28 - Vault Secrets Operator vulnerable to arbitrary file read via AppRole secretIDPath Security - HashiCorp Discuss

CSIRTS triage

What
The Vault Secrets Operator is vulnerable to arbitrary file read through the AppRole secretIDPath parameter.
Who is affected
Deployments of Vault Secrets Operator versions before 1.5.0 are affected.
Urgency
Moderate urgency as the vulnerability allows information disclosure; no exploitation in the wild has been reported but the attack vector is direct.
Action
Upgrade Vault Secrets Operator to version 1.5.0 or later.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Vault Secrets Operator

Get an email when a new Vault Secrets Operator advisory drops — max one per day, one-click unsubscribe.

Details

Source
Canadian Centre for Cyber Security (CA · national-cert · site)
Severity
unknown
Published
2026-08-14
Exploitation
Not in CISA KEV at last sync

Original advisory: https://cyber.gc.ca/en/alerts-advisories/hashicorp-security-advisory-av26-817

More from Canadian Centre for Cyber Security