CVE-2026-89322
Received Received - Intake

ACL Policy Bypass in Vault and Vault Enterprise

Vulnerability report for CVE-2026-89322, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: HashiCorp Inc.

Description

Vault and Vault Enterprise did not consistently evaluate ACL policies against the canonical form of resource and policy names. This may allow an authenticated user with delegated permissions to bypass an explicit deny restriction and access a protected resource or assign a denied policy, potentially leading to privilege escalation. This vulnerability (CVE-2026-89322) is fixed in Vault Community Edition 2.1.2, and Vault Enterprise 2.1.2, 1.21.12, 1.20.17, and 1.19.23.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
HashiCorp Vault 0.0.1
HashiCorp Vault Enterprise 0.0.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-178 The product does not properly account for differences in case sensitivity when accessing or determining the properties of a resource, leading to inconsistent results.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves Vault and Vault Enterprise not consistently checking ACL policies against the standard form of resource and policy names. An authenticated user with delegated permissions could bypass an explicit deny restriction, potentially accessing protected resources or assigning denied policies, leading to privilege escalation.

Detection Guidance

This vulnerability requires checking Vault's version and configuration for ACL policy inconsistencies. Use commands like 'vault version' to verify if your system is running a vulnerable version. Compare installed versions against the fixed releases (2.1.2 for Community, 2.1.2/1.21.12/1.20.17/1.19.23 for Enterprise). Review ACL policies for any explicit deny rules that may have been bypassed due to inconsistent evaluation.

Impact Analysis

If exploited, this vulnerability could allow unauthorized access to sensitive resources or policies, enabling attackers to escalate privileges within the system. This could lead to data breaches, unauthorized modifications, or other security incidents depending on the system's configuration.

Compliance Impact

This vulnerability could lead to unauthorized access or modifications, violating data protection requirements under GDPR and HIPAA. Non-compliance may result in legal penalties, reputational damage, and loss of trust due to potential data exposure or integrity breaches.

Mitigation Strategies

Upgrade to Vault Community Edition 2.1.2 or Vault Enterprise versions 2.1.2, 1.21.12, 1.20.17, or 1.19.23 or later to address the vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89322. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart