云虫漏洞库

CVE-2026-8715 - Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication configuration that may allow a tenant with limited Kubernetes RBAC permissions to read files from the operator pod's filesystem and transmit their contents to a tenant-controlled endpoint, potentially leading to privilege escalation within the cluster. This vulnerability (CVE-2026-8715) is fixed in Vault Secrets Operator 1.5.0. - 漏洞详情

漏洞编号:CVE-2026-8715

风险等级:危急

漏洞来源:CVE

CVE 编号:CVE-2026-8715

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-552

发布/更新时间:2026-08-13 / 2026-08-28

漏洞描述

Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication configuration that may allow a tenant with limited Kubernetes RBAC permissions to read files from the operator pod's filesystem and transmit their contents to a tenant-controlled endpoint, potentially leading to privilege escalation within the cluster. This vulnerability (CVE-2026-8715) is fixed in Vault Secrets Operator 1.5.0.

相关链接

相关漏洞

« 返回首页