v2.1.0
2026-09-02T08:52:04Z•ca8ef1f21d95e946f19980a1ea1b8f6bc180e140d4add9186e54f6bd0d7f809d
CVE-2026-1229CVE-2026-34986CVE-2026-39829CVE-2026-39883AI agentsHashiCorp VaultOAuthPKISSHaccess controlauthentication bypasscryptographydependency updatesidentity managementnamespace isolationprivilege escalationrelease notes
What happened
HashiCorp Vault releases v2.0.0 through v2.1.0 contain multiple security fixes, including ACL and authentication bypass prevention, identity and namespace authorization hardening, recovery-token constant-time comparison, template escaping, dependency vulnerability remediation, and SSH RSA key-size limits. The latest v2.1.0 updates etcd and PKCS#12 dependencies for GO-2026-6107 and GO-2026-5052. Administrators should upgrade promptly and review breaking container and policy behavior changes.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- hashicorp_vault_releases
- Record identifier
- ca8ef1f21d95e946f19980a1ea1b8f6bc180e140d4add9186e54f6bd0d7f809d
- Enrichment time
- 2026-09-02T08:52:04Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.