Authorization Bypass Vulnerability in HashiCorp Vault
CVE-2026-12624

4.3MEDIUM

Key Information:

Vendor

Hashicorp

Vendor
CVE Published:
10 August 2026

What is CVE-2026-12624?

The Vault's ACL policy engine fails to consistently enforce a wildcard deny rule against LIST requests made with a trailing slash on restricted paths. This inconsistency allows tokens, which should be subject to a deny rule, to enumerate entries beneath paths intended to be inaccessible. Fixes for this issue are implemented in specific versions of both Vault Community and Enterprise editions.

Affected Version(s)

Vault 64 bit 0 < 2.0.3

Vault Enterprise 64 bit 0 < 2.0.3

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was reported to HashiCorp by Mike Cole of Redpath Security.
.