CVE-2026-12624Patch

LOWCVSS 4.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Vault’s ACL policy engine did not consistently enforce a wildcard (glob) deny rule against LIST requests made with a trailing slash on the denied path. This may allow a token holding a broader allow rule alongside a narrower wildcard deny rule to enumerate the names of entries beneath a path it was intended to be denied access to. This vulnerability (CVE-2026-12624) is fixed in Vault Community Edition 2.0.3 and Vault Enterprise 2.0.3, 1.21.8, 1.20.13, and 1.19.19.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-12: 1Patch / Workaround · 2026-08-12: 1Technical Details · 2026-08-12: 108-12
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • HOL@HashgraphOnline
    Patch

    CVE-2026-12624: Vault's ACL engine skipped wildcard deny rules on LIST requests with a trailing slash, letting a token enumerate secret names under a path it was denied. Fixed in Vault CE 2.0.3, Enterprise 1.19.19+, 1.20.13+, 1.21.8+. CWE-863, no CVSS assigned yet. Details: https://hol.org/blog/cve-2026-12624-vault-list-auth-bypass

    Post summary

    CVE-2026-12624 describes an ACL bug in Vault that allows enumeration of secrets, but it has been patched in recent Vault releases, with no evidence of active exploitation reported.

    01060867
    19.2K followersView on X

Explore more