CVE WATCH / VULNERABILITY DETAIL

CVE-2026-105818

MEDIUMCVSS 5.9NVD feed

Published 7 October 2026 · tracked since 8 October 2026

Description

Vault's PKI secrets engine ACME server did not restrict certificate identities that ACME challenges do not validate when issuing certificates under the default directory policy. This may allow an ACME client to obtain a certificate containing unverified identity claims, potentially enabling imperson

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-105818 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-105818

MEDIUMCVSS 5.9NVD feed

Published 7 October 2026 · tracked since 8 October 2026

Description

Vault's PKI secrets engine ACME server did not restrict certificate identities that ACME challenges do not validate when issuing certificates under the default directory policy. This may allow an ACME client to obtain a certificate containing unverified identity claims, potentially enabling imperson

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]