v2.1.1

2026-09-17T08:52:05Z•235735bb897b8394e7756e0f745f081b62b0d45da9ce11d077554ecda8cfe589
CVE-2026-1229CVE-2026-34986CVE-2026-39829CVE-2026-39883ACL bypassGoHashiCorp VaultSCIMSSHVaultaccess controlauthentication bypasscryptographydependency vulnerabilitiesenterpriseidentity managementprivilege escalationsecurity release

What happened

HashiCorp Vault releases v2.0.0 through v2.1.1 include multiple security fixes affecting ACL enforcement, identity and SCIM authorization boundaries, authentication, cryptographic libraries, SSH key handling, audit API validation, and dependency vulnerabilities. The most significant issues include an AWS authentication bypass, ACL bypasses, privilege escalation through case-sensitive policy names, cross-namespace entity deletion protections, and CVE-2026-39829 involving oversized RSA keys. Vault operators should upgrade to the latest applicable release and review configuration and container mლ

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
hashicorp_vault_releases
Record identifier
235735bb897b8394e7756e0f745f081b62b0d45da9ce11d077554ecda8cfe589
Enrichment time
2026-09-17T08:52:05Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.