CVE-2026-88715

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-8715 describes an arbitrary file read and credential exfiltration vulnerability affecting Vault Secrets Operator versions 1.3.0 through 1.4.1. This flaw resides within the AppRole authentication configuration, specifically due to insufficient path validation for the `spec.appRole.secretIDPath` field. Exploitation of this vulnerability could allow a tenant with limited Kubernetes Role-Based Access Control (RBAC) permissions to read files from the operator pod's filesystem. The contents of these files could then be transmitted to a tenant-controlled endpoint, potentially leading to privilege escalation within the cluster. The issue is resolved in Vault Secrets Operator version 1.5.0.

Description
-

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

20

References

Sources include official advisories and independent security research.