---
id: CVE-2026-105820
title: >-
  Vault's ACL policy cache allowed namespace traversal when policy names
  contained path traversal constructs
summary: >-
  Vault's ACL policy cache allowed namespace traversal when policy names
  contained path traversal constructs. This may allow a token assigned specially
  crafted policy names to use the capabilities of policies defined in other
  namespaces, i…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-22
vendor: HashiCorp
product: Vault Enterprise
affected:
  - vault_enterprise >= 0.0.1 < 2.1.2
published: '2026-10-07'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T22:17:02.990'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105820'
references:
  - url: >-
      https://discuss.hashicorp.com/t/hcsec-2026-42-vault-enterprise-acl-policy-cache-vulnerable-to-cross-namespace-policy-resolution/77814
    label: security@hashicorp.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-07T22:59:42.830Z'
---

## Overview

Vault's ACL policy cache allowed namespace traversal when policy names contained path traversal constructs. This may allow a token assigned specially crafted policy names to use the capabilities of policies defined in other namespaces, including the root namespace. This vulnerability (CVE-2026-105820) is fixed in Vault Enterprise 2.1.2, 1.21.12, 1.20.17, and 1.19.23. Vault Community Edition does not support namespaces, and is not affected.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
