HashiCorp security advisory (AV26-1019)
Canada’s Cyber Centre warns older HashiCorp Vault builds allow code execution via Raft snapshot plugin entries.
The Canadian Centre for Cyber Security issued advisory AV26-1019 on October 8, 2026, for HashiCorp Vault vulnerabilities current as of October 7. Affected releases are Vault Community Edition before 2.1.2 and Vault Enterprise before 1.19.23, 1.20.17, 1.21.12, and 2.1.2. HashiCorp bulletin HCSEC-2026-41 says Vault is vulnerable to arbitrary code execution through plugin catalog entries restored from Raft snapshots. Administrators are told to review HashiCorp’s links and update; the alert states no CVE and no observed exploitation.
- CCCS advisory AV26-1019 covers HashiCorp Vault Community and Enterprise.
- Community builds before 2.1.2 and listed Enterprise builds are affected.
- HCSEC-2026-41 describes code execution via Raft snapshot plugin entries.
- The alert names no CVE and does not report active exploitation.
Full article88 words · extracted from cyber.gc.ca · click to collapse
Serial number: AV26-1019
Date: October 8, 2026
As of October 7, 2026, HashiCorp is affected by vulnerabilities in the following products:
- Vault Community Edition
- Prior to 2.1.2
- Vault Enterprise
- Prior to 1.19.23
- Prior to 1.20.17
- Prior to 1.21.12
- Prior to 2.1.2
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/hashicorp-security-advisory-av26-1019