Junglewise Threat Intelligence

CVE-2026-3605: HashiCorp Vault policy bypass in KVv2 secrets engine

CVE-2026-3605 · Severity: high · CVSS 8.1 · Published 2026-04-17

Technologies: HashiCorp Vault Community Edition, github.com/hashicorp/vault (Go), HashiCorp Vault Enterprise. Vendors: HashiCorp, Go.

Executive brief

HashiCorp Vault is a tool used to securely store and manage sensitive information like passwords and encryption keys. A vulnerability was found where an authorized user could bypass security policies to delete secrets they should not have access to. While this does not allow the attacker to read the secret data, it can lead to a denial-of-service by permanently removing critical credentials required for business operations.

Technical details

A policy bypass vulnerability exists in HashiCorp Vault's KVv2 secrets engine. Due to separate request flows for metadata and data, an authenticated user with a policy containing a glob pattern can bypass intended restrictions to delete secrets or metadata they are not authorized to modify. The attack requires the user to have some level of authenticated access to a KVv2 path. While the vulnerability allows for unauthorized deletion (Denial of Service), it does not permit unauthorized reading of secret data or cross-namespace deletion. The fix involves enforcing canonical paths for all KVv2 data and metadata requests.

Affected products

  • HashiCorp Vault Community Edition 0.10 up to 1.21.4, fixed in 2.0.0
  • HashiCorp Vault Enterprise 0.10 up to 1.21.4, 1.20.9, 1.19.15; fixed in 2.0.0, 1.21.5, 1.20.10, and 1.19.16

Timeline

  • 2026-04-16: advisory: HashiCorp published HCSEC-2026-05
  • 2026-04-17: disclosed: NVD publication date

References

Related threats