CVE-2026-105818: fallo de gravedad media en HashiCorp Vault
Vault PKI ACME Issues Certificate With Unvalidated SANs
Publicada el
10Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 5.9
probabilidad de explotación
—
explotación observada
noninguna fuente lo reporta
Vault's PKI secrets engine ACME server did not restrict certificate identities that ACME challenges do not validate when issuing certificates under the default directory policy. This may allow an ACME client to obtain a certificate containing unverified identity claims, potentially enabling impersonation toward systems that trust certificates issued by the affected Vault PKI mount. This vulnerability (CVE-2026-105818) is fixed in Vault Community Edition 2.1.2, and Vault Enterprise 2.1.2, 1.21.12, 1.20.17, and 1.19.23.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
CVEs relacionadas — HashiCorp Vault
En el mismo producto, de las más peligrosas a las menos.
CVE-2025-6000CRITICALArbitrary Remote Code Execution via Plugin Catalog AbuseEPSS 0.9%CVE-2026-5807HIGHVault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey OperationsEPSS 0.9%CVE-2023-6337HIGHVault May be Vulnerable to a Denial of Service Through Memory Exhaustion When Handling Large HTTP RequestsEPSS 0.8%CVE-2024-0831MEDIUMVault May Expose Sensitive Information When Configuring An Audit Log DeviceEPSS 0.8%CVE-2023-5954MEDIUMVault Requests Triggering Policy Checks May Lead To Unbounded Memory ConsumptionEPSS 0.7%CVE-2025-6203HIGHVault unauthenticated denial of service through complex json payloadEPSS 0.7%