{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/vault-enterprise--1.19.23--1.20.17--1.21.12--2.1.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Vault Community Edition (\u003c 2.1.2)","Vault Enterprise (\u003c 1.19.23, \u003c 1.20.17, \u003c 1.21.12, \u003c 2.1.2)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","remote-code-execution","hashicorp"],"_cs_type":"advisory","_cs_vendors":["HashiCorp"],"content_html":"\u003cp\u003eHashiCorp has released a security advisory regarding an arbitrary code execution (ACE) vulnerability in Vault Community Edition and Vault Enterprise (HCSEC-2026-41). The vulnerability occurs during the processing of plugin catalog entries that are restored from Raft snapshots. An attacker with sufficient privileges to modify the plugin catalog or supply a compromised Raft snapshot can introduce malicious entries, which are subsequently executed by the Vault process during restoration or startup. This allows an attacker to achieve code execution within the context of the Vault service, potentially compromising secrets, encryption keys, and the integrity of the entire Vault cluster. The issue affects Vault Community Edition versions prior to 2.1.2 and specific Vault Enterprise version branches (1.19.23, 1.20.17, 1.21.12, and 2.1.2).\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an attacker to gain arbitrary code execution on the Vault server, which is typically a high-value asset in infrastructure environments. Compromise of Vault leads to the exposure of stored secrets, certificates, and credentials, impacting the security posture of all systems relying on Vault for identity or secret management.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eApply the security updates for HashiCorp Vault immediately to the recommended versions: Vault Community Edition 2.1.2 or later, and Vault Enterprise 1.19.23, 1.20.17, 1.21.12, or 2.1.2 and later.\u003c/li\u003e\n\u003cli\u003eAudit access controls to the Raft snapshot management interfaces and plugin catalog configuration to ensure only authorized entities can perform modifications.\u003c/li\u003e\n\u003cli\u003eRestrict access to administrative APIs that allow triggering Raft snapshot restoration.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-08T19:43:08Z","date_published":"2026-10-08T19:43:08Z","id":"https://feed.craftedsignal.io/briefs/2026-10-hashicorp-vault-ace/","summary":"HashiCorp Vault is vulnerable to arbitrary code execution when restoring Raft snapshots containing malicious plugin catalog entries.","title":"Arbitrary Code Execution in HashiCorp Vault via Plugin Catalog","url":"https://feed.craftedsignal.io/briefs/2026-10-hashicorp-vault-ace/"}],"language":"en","title":"CraftedSignal Threat Feed - Vault Enterprise (\u003c 1.19.23, \u003c 1.20.17, \u003c 1.21.12, \u003c 2.1.2)","version":"https://jsonfeed.org/version/1.1"}