HashiCorp disclosed two security issues in Vault affecting availability and access controls. One advisory, HCSEC-2026-05, warns that Vault's KVv2 engine is vulnerable to a policy bypass involving metadata and secret deletion operations, creating a denial-of-service condition and allowing actions that should have been restricted by policy.
A second advisory, HCSEC-2026-08, says Vault is also vulnerable to denial of service through unauthenticated root token generation and rekey operations. Together, the disclosures indicate that both authenticated policy enforcement paths and unauthenticated operational workflows in Vault can be abused to disrupt service, underscoring the need for organizations running Vault to review affected deployments and apply vendor guidance promptly.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
HashiCorp published advisory HCSEC-2026-08 describing a Vault denial-of-service vulnerability tied to unauthenticated root token generation and rekey operations.
HashiCorp fixed CVE-2026-3605, a Vault KVv2 access-control flaw that let an authenticated user delete unauthorized secrets and trigger denial of service. The issue was addressed in Vault Community Edition 2.0.0 and Vault Enterprise 2.0.0, 1.21.5, 1.20.10, and 1.19.16.
HashiCorp published advisory HCSEC-2026-05 describing a Vault KVv2 vulnerability involving metadata and secret deletion policy bypass that can lead to denial of service.
HashiCorp published advisory HCSEC-2026-06 for a server-side request forgery vulnerability in Vault affecting ACME challenge validation through attacker-controlled DNS. The issue was included in the April 16, 2026 set of Vault security advisories referenced by the Canadian Centre for Cyber Security.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
cyber.gc.ca
Open sourcediscuss.hashicorp.com
Open sourcediscuss.hashicorp.com
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.