---
id: CVE-2026-89322
title: >-
  Vault and Vault Enterprise did not consistently evaluate ACL policies against
  the canonical form of resource and policy names
summary: >-
  Vault and Vault Enterprise did not consistently evaluate ACL policies against
  the canonical form of resource and policy names. This may allow an
  authenticated user with delegated permissions to bypass an explicit deny
  restriction and acc…
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-178
vendor: HashiCorp
product: Vault
affected:
  - Vault >= 0.0.1 < 2.1.2
  - vault_enterprise >= 0.0.1 < 2.1.2
published: '2026-10-07'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T23:17:01.197'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-89322'
references:
  - url: >-
      https://discuss.hashicorp.com/t/hcsec-2026-43-vault-inconsistent-acl-policy-evaluation-may-allow-bypass-of-deny-restrictions/77815
    label: security@hashicorp.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-07T22:59:42.835Z'
---

## Overview

Vault and Vault Enterprise did not consistently evaluate ACL policies against the canonical form of resource and policy names. This may allow an authenticated user with delegated permissions to bypass an explicit deny restriction and access a protected resource or assign a denied policy, potentially leading to privilege escalation. This vulnerability (CVE-2026-89322) is fixed in Vault Community Edition 2.1.2, and Vault Enterprise 2.1.2, 1.21.12, 1.20.17, and 1.19.23.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
