Known Vulnerabilities for Vault Enterprise by HashiCorp
Listed below are 7 of the newest known vulnerabilities associated with "Vault Enterprise" by "HashiCorp".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-19017 json | Consul Community Edition and Consul Enterprise 1.18.21 through 2.0.2 are vulnerable to a partial arbitrary file read when con... | Not Provided | 2026-08-07 | 2026-08-10 |
| CVE-2026-14886 json | Vault Enterprise's identity entity batch-delete endpoint is vulnerable to a cross-namespace authorization bypass that may all... | Not Provided | 2026-08-10 | 2026-08-12 |
| CVE-2026-12624 json | Vault’s ACL policy engine did not consistently enforce a wildcard (glob) deny rule against LIST requests made with a traili... | Not Provided | 2026-08-10 | 2026-08-11 |
| CVE-2026-5807 json | Vault is vulnerable to a denial-of-service condition where an unauthenticated attacker can repeatedly initiate or cancel root... | Not Provided | 2026-04-17 | 2026-07-15 |
| CVE-2026-5051 json | HashiCorp Vault and Vault Enterprise prior to 2.0.1 audit device validation logic did not consistently apply plugin directory... | Not Provided | 2026-07-01 | 2026-07-01 |
| CVE-2026-5006 json | A vulnerability was identified in HashiCorp Vault and Vault Enterprise (“Vault”) such that an authenticated attacker may ... | Not Provided | 2026-08-24 | 2026-08-26 |
| CVE-2026-3605 json | An authenticated user with access to a kvv2 path through a policy containing a glob may be able to delete secrets they were n... | Not Provided | 2026-04-17 | 2026-07-15 |