Vendor
HashiCorp vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 30 vulnerabilities in HashiCorp: 0 in the last 7 days and 20 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-88922, was published on 15 September 2026. 8 technologies have a page of their own.
- Last 7 days
- 0
- Last 90 days
- 20
- Critical, all time
- 2
- Exploited in the wild
- 0
About HashiCorp
A software company that provides open-source tools and commercial products for cloud infrastructure automation and management.
HashiCorp technologies
Latest HashiCorp vulnerabilities
- CVE-2026-88922: go-getter privilege escalation in archive decompressionmediumCVSS 6.7EPSS 0.1%
- CVE-2026-88021: HashiCorp Consul authorization bypass in Connect service meshhighCVSS 7.1EPSS 0.3%
- CVE-2026-87993: HashiCorp Consul-template information disclosure in error handlinghighCVSS 7.7EPSS 0.4%
- CVE-2026-87107: HashiCorp Consul authorization bypass in catalog deregistrationmediumCVSS 5.4EPSS 0.3%
- CVE-2026-87106: HashiCorp Consul denial of service in native RPC listenermediumCVSS 6.5EPSS 0.4%
- CVE-2026-87090: HashiCorp Consul authorization bypass in catalog node-writehighCVSS 8.3EPSS 0.4%
- CVE-2026-5006: HashiCorp Vault privilege escalation in templated policy pathsmediumCVSS 6.8EPSS 0.3%
- CVE-2026-12624: HashiCorp Vault ACL policy engine authorization bypass in LIST requestsmediumCVSS 4.3EPSS 0.3%
- CVE-2026-16328: HashiCorp consul-mcp-server SSRF and token exfiltrationhighCVSS 8.6
- CVE-2026-16326: HashiCorp consul-mcp-server session state leakage in stateless modecriticalCVSS 10
- CVE-2026-16498: HashiCorp terraform-mcp-server cross-tenant credential reuse in stateless modecriticalCVSS 10
- CVE-2026-16496: HashiCorp terraform-mcp-server auth bypass in stateful transport modehighCVSS 8.9
- CVE-2026-14869: HashiCorp terraform-mcp-server SSRF in streamable-HTTP transporthighCVSS 8.6
- CVE-2026-14896: HashiCorp Nomad authorization bypass in dynamic host volumesmediumCVSS 4.2
- CVE-2026-14891: HashiCorp Nomad sandbox escape in Docker task driverhighCVSS 8.7
- CVE-2026-14373: HashiCorp Nomad authorization bypass in Docker task driver host namespaceshighCVSS 7.7
- CVE-2026-14361: HashiCorp Consul-template path redirection in writeToFile helpermediumCVSS 4.7
- CVE-2026-14362: HashiCorp memberlist denial of service in push/pull state handlingmediumCVSS 4.9
- CVE-2026-14468: HashiCorp Terraform Enterprise path traversal in VCS module ingestionhighCVSS 7.7
- CVE-2026-5051: HashiCorp Vault path traversal in audit device validationmediumCVSS 4.4
- CVE-2026-8052: HashiCorp Nomad exec2 task driver symlink attack in log handlingmediumCVSS 6EPSS 0.0%
- CVE-2026-7474: HashiCorp Nomad path traversal in Dynamic Host VolumeshighCVSS 8.8EPSS 0.0%
- CVE-2026-6959: HashiCorp Nomad arbitrary file read and write via symlink attackmediumCVSS 6EPSS 0.0%
- CVE-2026-5061: HashiCorp consul-template sandbox path bypass in file helpermediumCVSS 4.7
- CVE-2026-7776: HashiCorp Boundary denial of service in worker node enrollmenthighCVSS 7.5EPSS 0.2%
Most severe HashiCorp vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-16326: HashiCorp consul-mcp-server session state leakage in stateless modecriticalCVSS 10
- CVE-2026-16498: HashiCorp terraform-mcp-server cross-tenant credential reuse in stateless modecriticalCVSS 10
- CVE-2026-16496: HashiCorp terraform-mcp-server auth bypass in stateful transport modehighCVSS 8.9
- CVE-2026-7474: HashiCorp Nomad path traversal in Dynamic Host VolumeshighCVSS 8.8EPSS 0.0%
- CVE-2026-14891: HashiCorp Nomad sandbox escape in Docker task driverhighCVSS 8.7
- CVE-2026-16328: HashiCorp consul-mcp-server SSRF and token exfiltrationhighCVSS 8.6
- CVE-2026-14869: HashiCorp terraform-mcp-server SSRF in streamable-HTTP transporthighCVSS 8.6
- CVE-2026-87090: HashiCorp Consul authorization bypass in catalog node-writehighCVSS 8.3EPSS 0.4%
- CVE-2026-3605: HashiCorp Vault policy bypass in KVv2 secrets enginehighCVSS 8.1EPSS 0.3%
- CVE-2026-87993: HashiCorp Consul-template information disclosure in error handlinghighCVSS 7.7EPSS 0.4%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 1 | 0 | |
| 6 Jul 2026 | 6 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 5 | 2 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 1 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 1 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 5 | 0 | |
| 14 Sep 2026 | 1 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/hashicorp.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "HashiCorp vulnerabilities", https://junglewise.ai/threats/vendors/hashicorp, 26 September 2026.