Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-89322

HIGH NVD
CVSS Score 7.2
Severity HIGH
Published Oct 07, 2026
Vendor unknown

Description

Vault and Vault Enterprise did not consistently evaluate ACL policies against the canonical form of resource and policy names. This may allow an authenticated user with delegated permissions to bypass an explicit deny restriction and access a protected resource or assign a denied policy, potentially leading to privilege escalation. This vulnerability (CVE-2026-89322) is fixed in Vault Community Edition 2.1.2, and Vault Enterprise 2.1.2, 1.21.12, 1.20.17, and 1.19.23.

References