Known Vulnerabilities for Vault by Hashicorp
Listed below are 10 of the newest known vulnerabilities associated with "Vault" by "Hashicorp".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-100287 json | Missing authorization in the attachment history API in Devolutions Server 2026.3.5.0 and earlier allows an authenticated low... | Not Provided | 2026-09-29 | 2026-09-29 |
| CVE-2026-97636 json | Apache Airflow HashiCorp provider: the HashiCorp Vault secrets backend's team-scope guard can be bypassed with a user-control... | Not Provided | 2026-09-24 | 2026-09-25 |
| CVE-2026-94416 json | An authorization bypass was found in the Ansible Automation Platform (AAP) gateway. The gateway API allows an authenticated a... | Not Provided | 2026-09-24 | 2026-09-24 |
| CVE-2026-93332 json | Improper access control in the partial connection API in Devolutions Server 2026.3.5.0 and earlier allows an authenticated l... | Not Provided | 2026-09-29 | 2026-09-30 |
| CVE-2026-90969 json | Improper access control in the vault entry listing feature in Devolutions Server 2026.2.16 and earlier allows an authenticat... | Not Provided | 2026-09-15 | 2026-09-20 |
| CVE-2026-87993 json | The consul-template library is vulnerable to an information disclosure issue in its error handling path that may allow Vault ... | Not Provided | 2026-09-10 | 2026-09-10 |
| CVE-2026-86808 json | A security vulnerability has been detected in moltis-org moltis up to 20260818.10. The affected element is the function vault... | Not Provided | 2026-09-08 | 2026-09-11 |
| CVE-2026-86465 json | Apache Airflow Akeyless provider: the Akeyless secrets backend's team-scope guard can be bypassed with a user-controlled key.... | Not Provided | 2026-09-16 | 2026-09-17 |
| CVE-2026-85178 json | Helicone's VaultManager.getDecryptedProviderKeyById() function in the GET /v1/vault/key/{providerKeyId} endpoint fails to val... | Not Provided | 2026-09-03 | 2026-09-24 |
| CVE-2026-84962 json | An unauthorized user with key vault write access may cause an authorized client to issue arbitrary authenticated Google Cloud... | Not Provided | 2026-09-03 | 2026-09-03 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Hashicorp | Vault | 1.7.0 | |||
| Application | Hashicorp | Vault | 1.7.0 | |||
| Application | Hashicorp | Vault | 1.6.3 | |||
| Application | Hashicorp | Vault | 1.6.3 | |||
| Application | Hashicorp | Vault | 1.6.2 | |||
| Application | Hashicorp | Vault | 1.6.2 | |||
| Application | Hashicorp | Vault | 1.6.1 | |||
| Application | Hashicorp | Vault | 1.6.1 | |||
| Application | Hashicorp | Vault | 1.6.0 | |||
| Application | Hashicorp | Vault | 1.6.0 | |||
| Application | Hashicorp | Vault | 1.5.7 | |||
| Application | Hashicorp | Vault | 1.5.7 | |||
| Application | Hashicorp | Vault | 1.5.6 | |||
| Application | Hashicorp | Vault | 1.5.6 | |||
| Application | Hashicorp | Vault | 1.5.5 | |||
| Application | Hashicorp | Vault | 1.5.5 | |||
| Application | Hashicorp | Vault | 1.5.4 | |||
| Application | Hashicorp | Vault | 1.5.4 | |||
| Application | Hashicorp | Vault | 1.5.3 | |||
| Application | Hashicorp | Vault | 1.5.3 |