CVE-2026-89322: fallo de gravedad alta en HashiCorp Vault
Vault ACL Policy Evaluation May Allow Bypass of Deny Restrictions
Publicada el
18Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 7.2
probabilidad de explotación
—
explotación observada
noninguna fuente lo reporta
Vault and Vault Enterprise did not consistently evaluate ACL policies against the canonical form of resource and policy names. This may allow an authenticated user with delegated permissions to bypass an explicit deny restriction and access a protected resource or assign a denied policy, potentially leading to privilege escalation. This vulnerability (CVE-2026-89322) is fixed in Vault Community Edition 2.1.2, and Vault Enterprise 2.1.2, 1.21.12, 1.20.17, and 1.19.23.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVEs relacionadas — HashiCorp Vault
En el mismo producto, de las más peligrosas a las menos.
CVE-2025-6000CRITICALArbitrary Remote Code Execution via Plugin Catalog AbuseEPSS 0.9%CVE-2026-5807HIGHVault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey OperationsEPSS 0.9%CVE-2023-6337HIGHVault May be Vulnerable to a Denial of Service Through Memory Exhaustion When Handling Large HTTP RequestsEPSS 0.8%CVE-2024-0831MEDIUMVault May Expose Sensitive Information When Configuring An Audit Log DeviceEPSS 0.8%CVE-2023-5954MEDIUMVault Requests Triggering Policy Checks May Lead To Unbounded Memory ConsumptionEPSS 0.7%CVE-2025-6203HIGHVault unauthenticated denial of service through complex json payloadEPSS 0.7%