PT-2026-33397 · Hashicorp+1 · Vault Enterprise+2
CVSS v2.0
8.5
High
| Vector | AV:N/AC:L/Au:S/C:N/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
HashiCorp Vault Community Edition versions prior to 2.0.0
HashiCorp Vault Enterprise versions prior to 1.19.16
HashiCorp Vault Enterprise versions prior to 1.20.10
HashiCorp Vault Enterprise versions prior to 2.0.0
Description
An authenticated user with access to a kvv2 path through a policy containing a glob may be able to delete secrets they were not authorized to read or write, which can lead to a denial-of-service. This issue does not allow the deletion of secrets across namespaces or the reading of secret data.
Recommendations
Update HashiCorp Vault Community Edition to version 2.0.0.
Update HashiCorp Vault Enterprise to version 1.19.16, 1.20.10, or 2.0.0.
Exploit
Fix
DoS
LPE
IDOR
Authentication Bypass Using an Alternate Path or Channel
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Red Os
Vault Community Edition
Vault Enterprise