HCSEC-2026-42 - Vault Enterprise ACL Policy Cache Vulnerable to Cross-Namespace Policy Resolution

Bulletin ID: HCSEC-2026-42

Affected Products / Versions: Vault Enterprise up to 2.1.1; fixed in Vault Enterprise 2.1.2, 1.21.12, 1.20.17, and 1.19.23.

Publication Date: October 7, 2026

Summary

Vault’s ACL policy cache allowed namespace traversal when policy names contained path traversal constructs. This may allow a token assigned specially crafted policy names to use the capabilities of policies defined in other namespaces, including the root namespace. This vulnerability (CVE-2026-105820) is fixed in Vault Enterprise 2.1.2, 1.21.12, 1.20.17, and 1.19.23. Vault Community Edition does not support namespaces, and is not affected.

Background

Vault Enterprise namespaces provide isolated environments within a single Vault cluster, each with its own policies, authentication methods, and secrets engines. Policies attached to a token are resolved within the token’s namespace, so a token’s access is limited to the namespaces it is authorized for. Vault caches policies in memory to avoid reading them from storage on every request. See the Namespaces documentation for more information.

Details

Vault did not prevent policy names from referencing other namespaces via path traversal constructs, and its in-memory policy cache could resolve such a policy belonging to a different namespace. A token assigned such a policy name could then be granted that policy’s capabilities within the policy’s own namespace, allowing the token to act across namespace boundaries. Exploitation requires an authenticated user able to assign arbitrary policy names to a token, for example through token creation or an auth method role. The referenced policy must be present in Vault’s policy cache both when the token is created and when it is used. When the referenced policy is the root policy of another namespace, its capabilities are granted only within the token’s own namespace.

Remediation

Customers should evaluate the risk associated with this issue and consider upgrading to Vault Enterprise 2.1.2, 1.21.12, 1.20.17, or 1.19.23. Because namespaces are a Vault Enterprise feature, the Vault Community Edition is not affected, but includes these changes as defense-in-depth hardening. After upgrading, policy names containing . or .. path segments are rejected for new policies and assignments, and are ignored for existing tokens and identities, which may reduce their effective permissions; operators should audit and rename any such policies before upgrading.

Acknowledgement

This issue was identified by an external party.