HCSEC-2026-41

HCSEC-2026-41 - Vault Vulnerable to Arbitrary Code Execution via Plugin Catalog Entries Restored From Raft Snapshots

Published
October 7, 2026
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

Bulletin ID: HCSEC-2026-41 Affected Products / Versions: Vault Community Edition and Vault Enterprise up to 2.1.1; fixed in Vault Community Edition 2.1.2, and Vault Enterprise 2.1.2, 1.21.12, 1.20.17, and 1.19.23. Publication Date: October 7, 2026 Summary Vault and Vault Enterprise did not consistently verify that stored plugin catalog entries reference binaries within the configured plugin directory. When Vault uses Shamir seals and has an external plugin directory configured, a privileged operator able to restore an Integrated Storage (Raft) snapshot may be able to execute arbitrary code on the Vault host. This vulnerability (CVE-2026-105816) is fixed in Vault Community Edition 2.1.2, and Vault Enterprise 2.1.2, 1.21.12, 1.20.17, and 1.19.23. Background Vault supports external plugins, which are registered in the plugin catalog and executed from the directory configured by plugin_directory. Vault restricts plugin registration so that execution of registered plugin binaries resolves within this directory, limiting executables to the operator-configured plugin directory. Integrated Storage supports saving and restoring snapshots of Vault’s data, including the plugin catalog. Details Vault verified that the executable resolved within the configured plugin directory (directly and after following symbolic links) when a plugin was registered, but not when a stored catalog entry was later used to run a plugin. A plugin catalog entry introduced without going through registration, such as through a restored snapshot, could reference a binary outside the plugin directory. Vault could then execute that binary as the Vault service user when the plugin was used, including during unseal for existing mounts. Exploitation requires a privileged operator able to restore snapshots. This issue only affects clusters using Shamir seals with an external plugin directory configured. Clusters using auto-unseal, or without a configured plugin directory, are not affected. Remediation Cust…

🎯 Affected products2

  • Vault
  • Vault Enterprise

🔗 References (1)