HCSEC-2026-42 - Vault Enterprise ACL Policy Cache Vulnerable to Cross-Namespace Policy Resolution
🔗 CVE IDs covered (1)
📋 Description
Bulletin ID: HCSEC-2026-42 Affected Products / Versions: Vault Enterprise up to 2.1.1; fixed in Vault Enterprise 2.1.2, 1.21.12, 1.20.17, and 1.19.23. Publication Date: October 7, 2026 Summary Vault’s ACL policy cache allowed namespace traversal when policy names contained path traversal constructs. This may allow a token assigned specially crafted policy names to use the capabilities of policies defined in other namespaces, including the root namespace. This vulnerability (CVE-2026-105820) is fixed in Vault Enterprise 2.1.2, 1.21.12, 1.20.17, and 1.19.23. Vault Community Edition does not support namespaces, and is not affected. Background Vault Enterprise namespaces provide isolated environments within a single Vault cluster, each with its own policies, authentication methods, and secrets engines. Policies attached to a token are resolved within the token’s namespace, so a token’s access is limited to the namespaces it is authorized for. Vault caches policies in memory to avoid reading them from storage on every request. See the Namespaces documentation for more information. Details Vault did not prevent policy names from referencing other namespaces via path traversal constructs, and its in-memory policy cache could resolve such a policy belonging to a different namespace. A token assigned such a policy name could then be granted that policy’s capabilities within the policy’s own namespace, allowing the token to act across namespace boundaries. Exploitation requires an authenticated user able to assign arbitrary policy names to a token, for example through token creation or an auth method role. The referenced policy must be present in Vault’s policy cache both when the token is created and when it is used. When the referenced policy is the root policy of another namespace, its capabilities are granted only within the token’s own namespace. Remediation Customers should evaluate the risk associated with this issue and consider upgrading to Vault Enterp…
🎯 Affected products2
- Vault Enterprise
- Vault