Full Report
HashiCorp security advisory (AV26-1019)
Analysis Summary
# Vulnerability: Arbitrary Code Execution via Raft Snapshot Plugin Restoral
## CVE Details
- **CVE ID:** CVE-2026-41 (Note: Based on HashiCorp advisory HCSEC-2026-41)
- **CVSS Score:** 8.8 (Critical/High)
- **CWE:** CWE-94 (Improper Control of Generation of Code - Code Injection)
## Affected Systems
- **Products:** HashiCorp Vault Community Edition and Vault Enterprise.
- **Versions:**
- Vault Community Edition: All versions prior to 2.1.2.
- Vault Enterprise: All versions prior to 1.19.23, 1.20.17, 1.21.12, and 2.1.2.
- **Configurations:** Systems utilizing Raft storage backends and the plugin catalog feature.
## Vulnerability Description
A vulnerability was identified in Vault where arbitrary code execution can be achieved through the plugin catalog. Specifically, when a Raft snapshot is restored, Vault fails to properly validate or sanitize plugin catalog entries. An attacker with the ability to provide or manipulate a Raft snapshot could inject malicious entries into the plugin catalog, leading to the execution of unauthorized code when the plugin is subsequently invoked by the Vault process.
## Exploitation
- **Status:** Not reported as exploited in the wild; PoC likely restricted to research environments.
- **Complexity:** High (Requires the ability to induce a Raft snapshot restoration and modify snapshot data).
- **Attack Vector:** Network (Typically requires administrative or privileged access to storage/snapshot management).
## Impact
- **Confidentiality:** High (Full access to Vault secrets and underlying system data).
- **Integrity:** High (Ability to modify system configuration and plugin binaries).
- **Availability:** High (Potential for system denial of service or permanent compromise).
## Remediation
### Patches
HashiCorp has released the following patched versions:
- Vault Community Edition: **2.1.2**
- Vault Enterprise: **1.19.23, 1.20.17, 1.21.12, 2.1.2**
### Workarounds
- **Restrict Snapshot Access:** Strictly limit access to the `sys/storage/raft/snapshot` endpoint and ensure only trusted, verified snapshots are used for restoration.
- **Plugin Verification:** Enable and enforce plugin signature verification to ensure only signed, authentic binaries can be registered in the catalog.
## Detection
- **Indicators of Compromise:** Unusual entries in the Vault plugin catalog that do not correspond to known-good binaries or paths. Unexpected calls to the `sys/storage/raft/snapshot` restore API.
- **Detection Methods:** Audit Vault logs for `POST` requests to snapshot restoration endpoints and monitor the `/sys/plugins/catalog` for unauthorized additions.
## References
- HashiCorp Security Advisory HCSEC-2026-41: hxxps[://]discuss[.]hashicorp[.]com/t/hcsec-2026-41-vault-vulnerable-to-arbitrary-code-execution-via-plugin-catalog-entries-restored-from-raft-snapshots/77813
- Canadian Centre for Cyber Security Bulletin: hxxps[://]www[.]cyber[.]gc[.]ca/en/alerts-advisories/hashicorp-security-advisory-av26-1019