{"type":"bundle","id":"bundle--08ca6d93-258a-5df4-a8be-f8820c96446c","objects":[{"type":"campaign","spec_version":"2.1","id":"campaign--233302a6-1862-5170-91d8-51b4229ebdb2","created":"2026-09-20T19:00:47.836Z","modified":"2026-09-20T19:00:47.836Z","name":"HashiCorp Vault LIST authorization bypass via trailing slash","description":"HashiCorp Vault LIST authorization bypass via trailing slash. Upgrade to the patched release.","aliases":["CVE-2026-12624"],"first_seen":"2026-08-12T00:00:00.000Z","last_seen":"2026-08-12T12:00:00.000Z","objective":"Defensive public threat-intelligence record; see limitations and source references.","external_references":[{"source_name":"NVD CVE-2026-12624","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-12624"},{"source_name":"HOL Guard operator write-up","url":"https://hol.org/blog/cve-2026-12624-vault-list-auth-bypass"},{"source_name":"CVE Record CVE-2026-12624","url":"https://www.cve.org/CVERecord?id=CVE-2026-12624"}]}]}