
CVE-2026-12624: Vault's ACL engine skipped wildcard deny rules on LIST requests with a trailing slash, letting a token enumerate secret names under a path it was denied. Fixed in Vault CE 2.0.3, Enterprise 1.19.19+, 1.20.13+, 1.21.8+. CWE-863, no CVSS assigned yet. Details: https://hol.org/blog/cve-2026-12624-vault-list-auth-bypass
Post summary
CVE-2026-12624 describes an ACL bug in Vault that allows enumeration of secrets, but it has been patched in recent Vault releases, with no evidence of active exploitation reported.
