Executive brief
Vault is a widely-used secrets management platform that enforces access control through ACL policies. An attacker with an authenticated token and specific policy permissions could bypass wildcard deny rules by making LIST requests with a trailing slash, allowing unauthorized enumeration of secret path names. While this does not expose secret values themselves, it reveals the structure and names of protected secrets, which can aid in further attacks.
Technical details
The vulnerability is an authorization bypass in Vault's ACL policy engine affecting LIST requests. When a LIST request is made against a denied path with a trailing slash, the policy engine normalizes the request path before performing a prefix lookup, causing it to incorrectly match a broader allow rule instead of the intended more-specific wildcard deny rule. This affects only authenticated tokens that already possess both a broad allow capability on a parent path and a narrower wildcard deny rule—tokens without this specific policy combination are unaffected. The issue is limited to disclosure of entry names via LIST operations; secret values remain protected and no capabilities beyond listing are granted. Fixes are available in Vault 2.0.3, Vault Enterprise 2.0.3, 1.21.8, 1.20.13, and 1.19.19.
Affected products
- HashiCorp Vault up to 2.0.2
- HashiCorp Vault Enterprise up to 2.0.2; 1.21.x before 1.21.8; 1.20.x before 1.20.13; 1.19.x before 1.19.19
Timeline
- 2026-08-10: disclosed: Vulnerability publicly disclosed via HashiCorp security advisory HCSEC-2026-26
- 2026-08-10: patched: Fixed in Vault 2.0.3, Vault Enterprise 2.0.3, 1.21.8, 1.20.13, and 1.19.19