Known Vulnerabilities for Vault by HashiCorp
Listed below are 10 of the newest known vulnerabilities associated with "Vault" by "HashiCorp".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-86808 json | A security vulnerability has been detected in moltis-org moltis up to 20260818.10. The affected element is the function vault... | Not Provided | 2026-09-08 | 2026-09-08 |
| CVE-2026-85178 json | Helicone's VaultManager.getDecryptedProviderKeyById() function in the GET /v1/vault/key/{providerKeyId} endpoint fails to val... | Not Provided | 2026-09-03 | 2026-09-03 |
| CVE-2026-84962 json | An unauthorized user with key vault write access may cause an authorized client to issue arbitrary authenticated Google Cloud... | Not Provided | 2026-09-03 | 2026-09-03 |
| CVE-2026-81681 json | openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 advertise a portable USB workspace as an 'Encrypted USB Works... | Not Provided | 2026-08-27 | 2026-08-27 |
| CVE-2026-81319 json | Deserialization of Untrusted Data vulnerability in ash-project ash_cloak allows an attacker who can influence the bytes of an... | Not Provided | 2026-08-30 | 2026-09-01 |
| CVE-2026-76362 json | In Splunk SOAR versions below 8.6.0, an unauthenticated user who can observe or alter network traffic between Splunk SOAR and... | Not Provided | 2026-08-19 | 2026-08-21 |
| CVE-2026-75137 json | UpSignOn for Windows before 7.19.0 contains a sensitive data exposure vulnerability that allows local attackers to recover cl... | Not Provided | 2026-09-02 | 2026-09-03 |
| CVE-2026-75136 json | UpSignOn for Windows before 7.19.0 contains an insecure credential storage vulnerability that allows local attackers to retri... | Not Provided | 2026-09-02 | 2026-09-03 |
| CVE-2026-75135 json | UpSignOn for Windows before 7.19.0 contains a sensitive data exposure vulnerability that allows local attackers to recover th... | Not Provided | 2026-09-02 | 2026-09-05 |
| CVE-2026-70619 json | Odysseus before commit bf325f6 contains a missing authorization vulnerability that allows authenticated non-admin users to ma... | Not Provided | 2026-08-04 | 2026-08-05 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Hashicorp | Vault | 1.7.0 | |||
| Application | Hashicorp | Vault | 1.7.0 | |||
| Application | Hashicorp | Vault | 1.6.3 | |||
| Application | Hashicorp | Vault | 1.6.3 | |||
| Application | Hashicorp | Vault | 1.6.2 | |||
| Application | Hashicorp | Vault | 1.6.2 | |||
| Application | Hashicorp | Vault | 1.6.1 | |||
| Application | Hashicorp | Vault | 1.6.1 | |||
| Application | Hashicorp | Vault | 1.6.0 | |||
| Application | Hashicorp | Vault | 1.6.0 | |||
| Application | Hashicorp | Vault | 1.5.7 | |||
| Application | Hashicorp | Vault | 1.5.7 | |||
| Application | Hashicorp | Vault | 1.5.6 | |||
| Application | Hashicorp | Vault | 1.5.6 | |||
| Application | Hashicorp | Vault | 1.5.5 | |||
| Application | Hashicorp | Vault | 1.5.5 | |||
| Application | Hashicorp | Vault | 1.5.4 | |||
| Application | Hashicorp | Vault | 1.5.4 | |||
| Application | Hashicorp | Vault | 1.5.3 | |||
| Application | Hashicorp | Vault | 1.5.3 |