BIT-vault-2026-12624

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/vault/BIT-vault-2026-12624.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-vault-2026-12624
Aliases
Published
2026-08-17T05:56:31.395Z
Modified
2026-08-17T08:02:00.049453131Z
Summary
Vault vulnerable to LIST authorization bypass via trailing-slash strip
Details

Vault’s ACL policy engine did not consistently enforce a wildcard (glob) deny rule against LIST requests made with a trailing slash on the denied path. This may allow a token holding a broader allow rule alongside a narrower wildcard deny rule to enumerate the names of entries beneath a path it was intended to be denied access to. This vulnerability (CVE-2026-12624) is fixed in Vault Community Edition 2.0.3 and Vault Enterprise 2.0.3, 1.21.8, 1.20.13, and 1.19.19.

Database specific
{
    "severity": "Medium",
    "cpes": [
        "cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:*",
        "cpe:2.3:a:hashicorp:vault:*:*:*:*:*:go:*:*"
    ]
}
References

Affected packages

Bitnami / vault

Package

Name
vault
Purl
pkg:bitnami/vault

Severity

  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.0.3

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/vault/BIT-vault-2026-12624.json"