CVE WATCH / VULNERABILITY DETAIL

CVE-2026-105816

HIGHCVSS 8NVD feed

Published 7 October 2026 · tracked since 8 October 2026

Description

Vault and Vault Enterprise did not consistently verify that stored plugin catalog entries reference binaries within the configured plugin directory. When Vault uses Shamir seals and has an external plugin directory configured, a privileged operator able to restore an Integrated Storage (Raft) snapsh

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-105816 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-105816

HIGHCVSS 8NVD feed

Published 7 October 2026 · tracked since 8 October 2026

Description

Vault and Vault Enterprise did not consistently verify that stored plugin catalog entries reference binaries within the configured plugin directory. When Vault uses Shamir seals and has an external plugin directory configured, a privileged operator able to restore an Integrated Storage (Raft) snapsh

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]