v2.0.4
2026-08-05T08:52:02Z•b4437e391b019b68b0fef1fe6dd1a804654493091452a53ec6a90307c55ad040
CVE-2026-1229CVE-2026-34986CVE-2026-39829CVE-2026-39883ACL bypassGo dependenciesHashiCorp VaultSCIMSSHVault Enterpriseaccess controlauthentication bypasscontainer securitycryptographydependency vulnerabilityidentity managementnamespace isolationpath traversalprivilege escalationsecurity update
What happened
HashiCorp Vault releases v2.0.0–v2.0.4 contain multiple security fixes, including ACL and identity authorization bypasses, authentication weaknesses, path handling issues, cryptographic timing improvements, dependency vulnerabilities, and an SSH RSA key-size limit addressing CVE-2026-39829. Vault operators should prioritize upgrading to v2.0.4 and review ACL, identity, SCIM, authentication, and container configuration changes.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- hashicorp_vault_releases
- Record identifier
- b4437e391b019b68b0fef1fe6dd1a804654493091452a53ec6a90307c55ad040
- Enrichment time
- 2026-08-05T08:52:02Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.