Improper Authorization in Vault Enterprise and Vault - CVE-2026-12624
Published: August 11, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the Vault ACL policy engine when handling LIST requests with a trailing slash on a denied path. A remote user can send a crafted LIST request to disclose sensitive information.
The issue is limited to enumeration of entry names beneath a denied path and does not disclose secret values. Exploitation requires a token that has both a broad allow rule on a parent path and a narrower wildcard deny rule on a subpath.
Affected software
Vault
How to mitigate CVE-2026-12624
Vault - update to 2.0.3