Improper access control in Vault Enterprise - CVE-2026-14886

 

Improper access control in Vault Enterprise - CVE-2026-14886

Published: August 11, 2026


Vulnerability identifier: #VU141395
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-14886
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to permanently delete entities belonging to another namespace.

The vulnerability exists due to improper access control in the identity entity batch-delete endpoint when handling batch-delete requests. A remote user can submit entity IDs from a different namespace to permanently delete entities belonging to another namespace.

The target entity may remain visible in memory until the identity store is reloaded from storage.


Affected software

Vault Enterprise

How to mitigate CVE-2026-14886

Install security update from vendor's website.

Vault Enterprise - addressed in versions 1.19.20, 1.20.14, 1.21.9, 2.0.4

External References

Related Security Bulletins