HashiCorp Vault Updates Prevent Unverified ACME Certificate Identities
Quick Answer
HashiCorp published HCSEC-2026-40 for Vault Community Edition and Vault Enterprise 1.14.0 through 2.1.1 with PKI ACME enabled and the sign-verbatim default directory policy. Inventory the exact affected scope, apply Vault Community Edition 2.1.2; Vault Enterprise 2.1.2, 1.21.12, 1.20.17, or 1.19.23, validate dependent operations, and preserve change evidence.
Validate Vault Scope And Apply The Supported Fix
What to do now: Inventory Vault Community Edition and Vault Enterprise 1.14.0 through 2.1.1 with PKI ACME enabled and the sign-verbatim default directory policy, match versions and enabled features to the authority's scope, apply supported remediation, validate representative operations, and document exceptions.
Last verified: 2026-10-08 UTC. Recheck the authoritative advisory and supported distribution channel before changing production.
Scope And Authority
| Product scope | Vault Community Edition and Vault Enterprise 1.14.0 through 2.1.1 with PKI ACME enabled and the sign-verbatim default directory policy |
|---|---|
| Advisory | HCSEC-2026-40 |
| CVE | CVE-2026-105818 |
| Authoritative release date | 2026-10-07 21:18:47.235 UTC |
| Authority revision date | 2026-10-07 21:18:47.235 UTC |
| Affected versions | Vault PKI mounts with ACME enabled and sign-verbatim used explicitly or by default; mounts that disable the default directory or constrain it with a role are not affected. |
| Fixed version | Vault Community Edition 2.1.2; Vault Enterprise 2.1.2, 1.21.12, 1.20.17, or 1.19.23 |
| CVSS base score | Not provided by the authority |
| CVSS severity | Not provided by the authority |
| Exploitation status | Not stated by the authority; no exploitation claim is inferred. |
What Changed
Vault PKI ACME could issue certificates containing identity claims that ACME challenges did not verify.
What To Validate Now
- Inventory. Locate Vault Community Edition and Vault Enterprise 1.14.0 through 2.1.1 with PKI ACME enabled and the sign-verbatim default directory policy; record versions, enabled features, exposure paths, owners, dependencies, support channels, and maintenance groups.
- Establish applicability. Compare every deployment with the authority's affected statement: Vault PKI mounts with ACME enabled and sign-verbatim used explicitly or by default; mounts that disable the default directory or constrain it with a role are not affected. Do not infer applicability from product family, CVSS, or Internet reachability alone.
- Remediate. Apply Vault Community Edition 2.1.2; Vault Enterprise 2.1.2, 1.21.12, 1.20.17, or 1.19.23 through the authority-supported channel and follow the current advisory.
- Validate. Confirm the resulting Vault build or managed state, exercise representative services and recovery paths, monitor for regressions, and retain the result.
- Retain evidence. Preserve asset and owner identifiers, the applicability decision, before-and-after versions, change approval, installation output, validation results, and any exception or rollback record.
Operational Cautions
Before upgrading, inventory PKI mounts and default_directory_policy values. If necessary, temporarily use a constraining role or disable the default directory as HashiCorp describes. Preserve pre-change state, installation output, logs, validation evidence, and rollback decisions.
Evidence To Retain
- Exact product, release stream, package or application version, enabled feature, environment, and accountable owner.
- UTC timestamps, authority revision, approved change record, installer or package-manager output, and resulting version.
- Relevant logs and monitoring evidence, test results, exceptions, compensating controls, and rollback decisions.
Related TechGeeks Resources
Authoritative References
Correction policy: If the authority changes affected versions, fixed versions, severity, exploitation information, mitigations, or required action, TechGeeks will update this notice and its verification date.

