CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-8715

criticalCVSS 9.6covered by 2 sourcesfirst seen 2026-08-13
A remote, authenticated attacker can exploit a vulnerability in Hashicorp Vault Secrets Operator to escalate privileges and disclose or manipulate data.

CSIRTS triage

What
Vault Secrets Operator contains a vulnerability allowing authenticated remote attackers to escalate privileges and disclose or manipulate data.
Who is affected
Authenticated users of Hashicorp Vault Secrets Operator installations can exploit this vulnerability.
Urgency
High urgency; privilege escalation in a secrets management tool poses critical risk to infrastructure security.
Action
Update Hashicorp Vault Secrets Operator to a patched version addressing CVE-2026-8715.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-8715

Get an email if CVE-2026-8715 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-8715

CVE.org record

Embed the live status

CVE-2026-8715 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-8715 status](https://www.csirts.com/badge/CVE-2026-8715)](https://www.csirts.com/cve/CVE-2026-8715)