PT-2026-69874 · Hashicorp · Vault Enterprise+1
CVE-2026-12624
·
Published
2026-08-10
·
Updated
2026-08-17
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Vault Community Edition versions prior to 2.0.3
Vault Enterprise versions prior to 2.0.3
Vault Enterprise versions prior to 1.21.8
Vault Enterprise versions prior to 1.20.13
Vault Enterprise versions prior to 1.19.19
Description
The ACL policy engine fails to consistently enforce wildcard (glob) deny rules during LIST requests when a trailing slash is used on the denied path. This allows a token that possesses both a broad allow rule and a narrow wildcard deny rule to enumerate entry names within a path that should be restricted.
Recommendations
Update Vault Community Edition to version 2.0.3.
Update Vault Enterprise to version 2.0.3, 1.21.8, 1.20.13, or 1.19.19.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vault Community Edition
Vault Enterprise