High severity8.0NVD Advisory· Published Oct 7, 2026
CVE-2026-105816
CVE-2026-105816
Description
Vault and Vault Enterprise did not consistently verify that stored plugin catalog entries reference binaries within the configured plugin directory. When Vault uses Shamir seals and has an external plugin directory configured, a privileged operator able to restore an Integrated Storage (Raft) snapshot may be able to execute arbitrary code on the Vault host. This vulnerability (CVE-2026-105816) is fixed in Vault Community Edition 2.1.2, and Vault Enterprise 2.1.2, 1.21.12, 1.20.17, and 1.19.23.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: before 2.1.2, 1.21.12, 1.20.17, 1.19.23
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.