SB2026081126 - Improper access control in HashiCorp Vault Enterprise
Published: August 11, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper access control (CVE-ID: CVE-2026-14886)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to permanently delete entities belonging to another namespace.
The vulnerability exists due to improper access control in the identity entity batch-delete endpoint when handling batch-delete requests. A remote user can submit entity IDs from a different namespace to permanently delete entities belonging to another namespace.
The target entity may remain visible in memory until the identity store is reloaded from storage.
Remediation
Install update from vendor's website.