Vulnerabilidades em HashiCorp

125 resultados
Análise Vexday

Com 93 CVEs catalogadas e nenhuma registrada no CISA KEV, o perfil de risco ativo da HashiCorp situa-se abaixo da média geral do catálogo, indicando ausência de exploração confirmada em campo até o momento. As 3 vulnerabilidades de severidade crítica e as 10 surgidas nos últimos 90 dias merecem acompanhamento próximo, especialmente CVE-2026-7474, que concentra o maior escore EPSS observado no portfólio (0,0689) e representa o vetor de maior probabilidade de exploração a curto prazo. A falha mais recorrente por tipo é CWE-266 (controle incorreto de privilégios), o que sugere atenção às configurações de permissão e ao modelo de confiança em ambientes que utilizam ferramentas HashiCorp para gestão de credenciais e infraestrutura. A ausência de PoCs públicas conhecidas reduz a superfície de ataque imediata, mas não elimina a necessidade de aplicar correções com regularidade, dado o ritmo recente de novas descobertas.

CVE-2026-19012MEDIUMAuthenticated denial of service in Consul Enterprise-to-Community Edition downgrade pathEPSS 0.2%CVE-2026-88021HIGHConsul vulnerable to an authorization bypass in the Connect service meshEPSS 0.2%CVE-2026-14886HIGHVault Enterprise vulnerable to cross-namespace entity deletionEPSS 0.2%CVE-2026-87106MEDIUMConsul vulnerable to a denial of service in the native RPC listenerEPSS 0.2%CVE-2026-16328HIGHconsul-mcp-server vulnerable to server side request forgery leading to token exposureEPSS 0.2%CVE-2026-87107MEDIUMConsul vulnerable to an authorization bypass in the catalog deregistration pathEPSS 0.2%CVE-2023-5834LOWVagrant’s Windows Installer Allowed Directory Junction WriteEPSS 0.2%CVE-2026-19016MEDIUMAuthorization bypass for session deletion in the transaction APIEPSS 0.2%CVE-2023-25000MEDIUMVault Vulnerable to Cache-Timing Attacks During Seal and Unseal OperationsEPSS 0.2%CVE-2026-87090HIGHConsul vulnerable to an authorization bypass in the catalog node-write pathEPSS 0.2%CVE-2026-7776HIGHBoundary Workers Vulnerable to Denial of Service During TLS HandshakeEPSS 0.2%CVE-2026-12624MEDIUMVault vulnerable to LIST authorization bypass via trailing-slash stripEPSS 0.2%CVE-2025-13432MEDIUMTerraform Enterprise state versions can be created by users with specific permissions without sufficient write accessEPSS 0.2%CVE-2026-5006MEDIUMVault Vulnerable to Privilege Escalation via Slash Injection in Templated Policy PathsEPSS 0.2%CVE-2026-6959MEDIUMNomad vulnerable to arbitrary file read/write on client host through symlink attackEPSS 0.2%CVE-2024-2877MEDIUMVault Enterprise Leaks Sensitive HTTP Request Headers in the Audit Log When Deployed With a Performance Standby NodeEPSS 0.2%CVE-2026-15970MEDIUML7 intention authorization bypass via custom public listenerEPSS 0.2%CVE-2026-5061MEDIUMConsul-template vulnerable to sandbox path bypass in file helper via a symlink attackEPSS 0.2%CVE-2026-19589HIGHPacker vulnerable to arbitrary file write via crafted plugin archive during installationEPSS 0.1%CVE-2024-10228LOWVagrant VMWare Utility installation files vulnerable to modification by unprivileged userEPSS 0.1%