v2.1.1
2026-09-17T08:52:05Z•235735bb897b8394e7756e0f745f081b62b0d45da9ce11d077554ecda8cfe589
CVE-2026-1229CVE-2026-34986CVE-2026-39829CVE-2026-39883ACL bypassGoHashiCorp VaultSCIMSSHVaultaccess controlauthentication bypasscryptographydependency vulnerabilitiesenterpriseidentity managementprivilege escalationsecurity release
What happened
HashiCorp Vault releases v2.0.0 through v2.1.1 include multiple security fixes affecting ACL enforcement, identity and SCIM authorization boundaries, authentication, cryptographic libraries, SSH key handling, audit API validation, and dependency vulnerabilities. The most significant issues include an AWS authentication bypass, ACL bypasses, privilege escalation through case-sensitive policy names, cross-namespace entity deletion protections, and CVE-2026-39829 involving oversized RSA keys. Vault operators should upgrade to the latest applicable release and review configuration and container mლ
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- hashicorp_vault_releases
- Record identifier
- 235735bb897b8394e7756e0f745f081b62b0d45da9ce11d077554ecda8cfe589
- Enrichment time
- 2026-09-17T08:52:05Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.