CVE-2026-89322

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Vault and Vault Enterprise did not consistently evaluate ACL policies against the canonical form of resource and policy names. This may allow an authenticated user with delegated permissions to bypass an explicit deny restriction and access a protected resource or assign a denied policy, potentially leading to privilege escalation. This vulnerability (CVE-2026-89322) is fixed in Vault Community Edition 2.1.2, and Vault Enterprise 2.1.2, 1.21.12, 1.20.17, and 1.19.23.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-178

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-08: 110-08
Referenced assets1 URL
Full discourse1 post
  • nivelepsilon@FpeSre

    Vault had a permissions problem worthy of a horror novel: the policy said "deny," but a differently cased resource name could evade the restriction. CVE-2026-89322 exposes a mismatch between ACL evaluation and name normalization under specific delegated-access configurations. Patch it, and review mixed-case deny rules. Apparently capitalization is a security boundary. https://discuss.hashicorp.com/t/hcsec-2026-43-vault-inconsistent-acl-policy-evaluation-may-allow-bypass-of-deny-restrictions/77815

    0000033
    189 followersView on X

Explore more