Authorization-bypass
3 posts tagged with “Authorization-bypass”

CVE-2026-18348: Velociraptor NETWORK ACL Bypass via Upload VQL Plugins
Incorrect authorization (CWE-863, CVSS 4.1) in Velociraptor's upload_azure, upload_sftp, and upload_smb VQL plugins lets an analyst-role user bypass the NETWORK ACL for reconnaissance and data exfiltration. Fixed in 0.77.2.

CVE-2026-14886: Vault Enterprise Cross-Namespace Secret Access Bypass
HashiCorp Vault Enterprise contains an authorization bypass allowing tokens scoped to one namespace to access secrets in another namespace, breaking the isolation model multi-tenant deployments depend on.

CVE-2026-12624: HashiCorp Vault LIST Authorization Bypass via Trailing Slash
CVE-2026-12624 lets a Vault token enumerate secrets beneath a path a deny policy was supposed to block. The ACL engine failed to enforce wildcard deny rules on LIST requests with a trailing slash. Fixed in Vault 2.0.3.