SB2026081126 - Improper access control in HashiCorp Vault Enterprise



SB2026081126 - Improper access control in HashiCorp Vault Enterprise

Published: August 11, 2026

Security Bulletin ID SB2026081126
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper access control (CVE-ID: CVE-2026-14886)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to permanently delete entities belonging to another namespace.

The vulnerability exists due to improper access control in the identity entity batch-delete endpoint when handling batch-delete requests. A remote user can submit entity IDs from a different namespace to permanently delete entities belonging to another namespace.

The target entity may remain visible in memory until the identity store is reloaded from storage.


Remediation

Install update from vendor's website.