Vault
2 posts tagged with “Vault”

CVE-2026-14886: Vault Enterprise Cross-Namespace Secret Access Bypass
HashiCorp Vault Enterprise contains an authorization bypass allowing tokens scoped to one namespace to access secrets in another namespace, breaking the isolation model multi-tenant deployments depend on.

CVE-2026-12624: HashiCorp Vault LIST Authorization Bypass via Trailing Slash
CVE-2026-12624 lets a Vault token enumerate secrets beneath a path a deny policy was supposed to block. The ACL engine failed to enforce wildcard deny rules on LIST requests with a trailing slash. Fixed in Vault 2.0.3.