
Vault had a permissions problem worthy of a horror novel: the policy said "deny," but a differently cased resource name could evade the restriction. CVE-2026-89322 exposes a mismatch between ACL evaluation and name normalization under specific delegated-access configurations. Patch it, and review mixed-case deny rules. Apparently capitalization is a security boundary. https://discuss.hashicorp.com/t/hcsec-2026-43-vault-inconsistent-acl-policy-evaluation-may-allow-bypass-of-deny-restrictions/77815
