HashiCorp security advisory (AV26-817)
Serial number: AV26-817 Date: August 14, 2026 As of August 13, 2026, HashiCorp is affected by a vulnerability in the following product Vault Secrets Operator - Prior to 1.5.0 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. HCSEC-2026-28 - Vault Secrets Operator vulnerable to arbitrary file read via AppRole secretIDPath Security - HashiCorp Discuss
CSIRTS triage
- What
- The Vault Secrets Operator is vulnerable to arbitrary file read through the AppRole secretIDPath parameter.
- Who is affected
- Deployments of Vault Secrets Operator versions before 1.5.0 are affected.
- Urgency
- Moderate urgency as the vulnerability allows information disclosure; no exploitation in the wild has been reported but the attack vector is direct.
- Action
- Upgrade Vault Secrets Operator to version 1.5.0 or later.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Vault Secrets Operator
Get an email when a new Vault Secrets Operator advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/hashicorp-security-advisory-av26-817
More from Canadian Centre for Cyber Security
- unknownFreePBX security advisory (AV26-818)2026-08-14
- unknownZimbra security advisory (AV26-816)2026-08-14
- unknownWebPros security advisory (AV26-815)2026-08-13
- unknownGitLab security advisory (AV26-814)2026-08-13
- unknownAMD security advisory (AV26-813)2026-08-13