Skip to content
Threat Feed
high advisory

Arbitrary Code Execution in HashiCorp Vault via Plugin Catalog

HashiCorp Vault is vulnerable to arbitrary code execution when restoring Raft snapshots containing malicious plugin catalog entries.

HashiCorp has released a security advisory regarding an arbitrary code execution (ACE) vulnerability in Vault Community Edition and Vault Enterprise (HCSEC-2026-41). The vulnerability occurs during the processing of plugin catalog entries that are restored from Raft snapshots. An attacker with sufficient privileges to modify the plugin catalog or supply a compromised Raft snapshot can introduce malicious entries, which are subsequently executed by the Vault process during restoration or startup. This allows an attacker to achieve code execution within the context of the Vault service, potentially compromising secrets, encryption keys, and the integrity of the entire Vault cluster. The issue affects Vault Community Edition versions prior to 2.1.2 and specific Vault Enterprise version branches (1.19.23, 1.20.17, 1.21.12, and 2.1.2).

Impact

Successful exploitation allows an attacker to gain arbitrary code execution on the Vault server, which is typically a high-value asset in infrastructure environments. Compromise of Vault leads to the exposure of stored secrets, certificates, and credentials, impacting the security posture of all systems relying on Vault for identity or secret management.

Recommendation

  • Apply the security updates for HashiCorp Vault immediately to the recommended versions: Vault Community Edition 2.1.2 or later, and Vault Enterprise 1.19.23, 1.20.17, 1.21.12, or 2.1.2 and later.
  • Audit access controls to the Raft snapshot management interfaces and plugin catalog configuration to ensure only authorized entities can perform modifications.
  • Restrict access to administrative APIs that allow triggering Raft snapshot restoration.

Mitigations

Upgrade Vault Community Edition to 2.1.2 or Vault Enterprise to respective fixed version (1.19.23, 1.20.17, 1.21.12, 2.1.2)

immediate IT Operations

HCSEC-2026-41