THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-8715 (CRITICAL 9.6) — Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication configuration that may allow a tenant with limited Kubernetes RBAC permissions to read files from the operator pod's filesystem and tra

[NVD] CVE-2026-8715 (CRITICAL 9.6) — Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication configuration that may allow a tenant with limited Kubernetes RBAC permissions to read files from the operator pod's filesystem and tra

mednvdPublished 2026-08-13

CVE-2026-8715 CVSS: 9.6 CRITICAL Published: 2026-08-13T21:18:32.333

Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication configuration that may allow a tenant with limited Kubernetes RBAC permissions to read files from the operator pod's filesystem and transmit their contents to a tenant-controlled endpoin

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-8715