VulnSea

Vault vulnerabilities

CVEs whose affected-version data names the Vault package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

4 CVEsRSS

CVE-2026-89322High· 7.2
yesterday

Vault and Vault Enterprise did not consistently evaluate ACL policies against the canonical form of resource and policy names

Vault and Vault Enterprise did not consistently evaluate ACL policies against the canonical form of resource and policy names. This may allow an authenticated user with delegated permissions to bypass an explicit deny restriction and acc…

▾ TwilightHashiCorp · Vaultvia NVD
CVE-2026-105818Medium· 5.9
yesterday

Vault's PKI secrets engine ACME server did not restrict certificate identities that ACME challenges do not validate when issuing certificates under the default directory policy

Vault's PKI secrets engine ACME server did not restrict certificate identities that ACME challenges do not validate when issuing certificates under the default directory policy. This may allow an ACME client to obtain a certificate conta…

▾ SunlitHashiCorp · Vaultvia NVD
CVE-2026-105816High· 8.0
yesterday

Vault and Vault Enterprise did not consistently verify that stored plugin catalog entries reference binaries within the configured plugin directory

Vault and Vault Enterprise did not consistently verify that stored plugin catalog entries reference binaries within the configured plugin directory. When Vault uses Shamir seals and has an external plugin directory configured, a privileg…

▾ TwilightHashiCorp · Vaultvia NVD
CVE-2025-6203High· 7.5
1y ago

A malicious user may submit a specially-crafted complex payload that otherwise meets the default request size limit which results in excessive memory and CPU consumption of Vault

A malicious user may submit a specially-crafted complex payload that otherwise meets the default request size limit which results in excessive memory and CPU consumption of Vault. This may lead to a timeout in Vault’s auditing subroutine…

▾ Twilighthashicorp · vaultEPSS 0.70%via NVD
Vault vulnerabilities (CVEs) · VulnSea