Improper access control in Vault Enterprise - CVE-2026-14886
Published: August 11, 2026
Vulnerability details
The vulnerability allows a remote user to permanently delete entities belonging to another namespace.
The vulnerability exists due to improper access control in the identity entity batch-delete endpoint when handling batch-delete requests. A remote user can submit entity IDs from a different namespace to permanently delete entities belonging to another namespace.
The target entity may remain visible in memory until the identity store is reloaded from storage.