Critical severity9.6NVD Advisory· Published Aug 13, 2026
CVE-2026-8715
CVE-2026-8715
Description
Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication configuration that may allow a tenant with limited Kubernetes RBAC permissions to read files from the operator pod's filesystem and transmit their contents to a tenant-controlled endpoint, potentially leading to privilege escalation within the cluster. This vulnerability (CVE-2026-8715) is fixed in Vault Secrets Operator 1.5.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: 1.3.0 - 1.4.1
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.