HashiCorp disclosed CVE-2026-8715, a critical flaw in Vault Secrets Operator that allows arbitrary file reads and credential exfiltration through the AppRole secretIDPath configuration. The vulnerability affects versions 1.3.0 through 1.4.1 and can be exploited by a tenant with limited Kubernetes RBAC permissions to read files from the operator pod filesystem and send their contents to a tenant-controlled endpoint.
The issue could expose sensitive credentials and create a path to privilege escalation inside a Kubernetes cluster. HashiCorp addressed the flaw in Vault Secrets Operator 1.5.0, and the Canadian Centre for Cyber Security issued advisory AV26-817, referencing HashiCorp bulletin HCSEC-2026-28 and urging administrators to review the advisory and apply the available update.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
The Canadian Centre for Cyber Security published advisory AV26-817 about the HashiCorp Vault Secrets Operator vulnerability and urged users and administrators to review the linked advisories and apply updates. The notice references HashiCorp advisory HCSEC-2026-28 and states the product is affected as of August 13, 2026.
HashiCorp disclosed a critical arbitrary file read and credential exfiltration vulnerability in Vault Secrets Operator's AppRole secretIDPath configuration, affecting versions 1.3.0 through 1.4.1 / versions prior to 1.5.0. The issue allows a tenant with limited Kubernetes RBAC permissions to read files from the operator pod filesystem and send their contents to a tenant-controlled endpoint.
The vulnerability was fixed in Vault Secrets Operator version 1.5.0, with guidance to upgrade to 1.5.0 or later and remove unnecessary RBAC permissions. This remediation addresses the arbitrary file read and credential exposure issue tracked as CVE-2026-8715.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcecyber.gc.ca
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.