{"id":"CVE-2026-105820","title":"Vault's ACL policy cache allowed namespace traversal when policy names contained path traversal constructs","summary":"Vault's ACL policy cache allowed namespace traversal when policy names contained path traversal constructs. This may allow a token assigned specially crafted policy names to use the capabilities of policies defined in other namespaces, i…","severity":"medium","cvss":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","cwe":["CWE-22"],"vendor":"HashiCorp","product":"Vault Enterprise","affected":["vault_enterprise >= 0.0.1 < 2.1.2"],"published":"2026-10-07","updated":"2026-10-07","sourceUpdated":"2026-10-07T22:17:02.990","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105820","references":[{"url":"https://discuss.hashicorp.com/t/hcsec-2026-42-vault-enterprise-acl-policy-cache-vulnerable-to-cross-namespace-policy-resolution/77814","label":"security@hashicorp.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-07T22:59:42.830Z","slug":"CVE-2026-105820","body":"## Overview\n\nVault's ACL policy cache allowed namespace traversal when policy names contained path traversal constructs. This may allow a token assigned specially crafted policy names to use the capabilities of policies defined in other namespaces, including the root namespace. This vulnerability (CVE-2026-105820) is fixed in Vault Enterprise 2.1.2, 1.21.12, 1.20.17, and 1.19.23. Vault Community Edition does not support namespaces, and is not affected.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":29.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}