PT-2026-69914 · Hashicorp · Vault Enterprise

CVE-2026-14886

·

Published

2026-08-10

·

Updated

2026-08-24

CVSS v3.1

8.2

High

VectorAV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Vault Enterprise versions prior to 2.0.4 Vault Enterprise versions prior to 1.21.9 Vault Enterprise versions prior to 1.20.14 Vault Enterprise versions prior to 1.19.20
Description The identity entity batch-delete endpoint is subject to a cross-namespace authorization bypass. This flaw allows an authenticated user within one namespace to permanently delete the storage backing of entities located in a different namespace.
Recommendations Update to version 2.0.4 Update to version 1.21.9 Update to version 1.20.14 Update to version 1.19.20

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-VAULT-2026-14886
CVE-2026-14886

Affected Products

Vault Enterprise