{"schema_version":1,"title":"HashiCorp vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 30 vulnerabilities in HashiCorp: 0 in the last 7 days and 20 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-88922, was published on 15 September 2026. 8 technologies have a page of their own.","url":"https://junglewise.ai/threats/vendors/hashicorp","json_url":"https://junglewise.ai/threats/vendors/hashicorp.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/hashicorp","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":15,"all_time":30,"critical":2,"exploited":0,"last_7_days":0,"last_30_days":6,"last_90_days":20,"last_365_days":30},"latest":[{"cve":"CVE-2026-88922","cvss":6.7,"epss":0.0011,"slug":"cve-2026-88922-go-getter-privilege-escalation-in-archive-decompression","title":"go-getter privilege escalation in archive decompression","severity":"medium","exploited":false,"published_at":"2026-09-15T20:19:19.813+00:00","url":"https://junglewise.ai/threats/cve-2026-88922-go-getter-privilege-escalation-in-archive-decompression"},{"cve":"CVE-2026-88021","cvss":7.1,"epss":0.0034,"slug":"cve-2026-88021-hashicorp-consul-authorization-bypass-in-connect-service-mesh","title":"HashiCorp Consul authorization bypass in Connect service mesh","severity":"high","exploited":false,"published_at":"2026-09-10T19:17:39.25+00:00","url":"https://junglewise.ai/threats/cve-2026-88021-hashicorp-consul-authorization-bypass-in-connect-service-mesh"},{"cve":"CVE-2026-87993","cvss":7.7,"epss":0.0038,"slug":"cve-2026-87993-hashicorp-consul-template-information-disclosure-in-error","title":"HashiCorp Consul-template information disclosure in error handling","severity":"high","exploited":false,"published_at":"2026-09-10T19:17:39.13+00:00","url":"https://junglewise.ai/threats/cve-2026-87993-hashicorp-consul-template-information-disclosure-in-error"},{"cve":"CVE-2026-87107","cvss":5.4,"epss":0.0031,"slug":"cve-2026-87107-hashicorp-consul-authorization-bypass-in-catalog-deregistration","title":"HashiCorp Consul authorization bypass in catalog deregistration","severity":"medium","exploited":false,"published_at":"2026-09-10T19:17:37.413+00:00","url":"https://junglewise.ai/threats/cve-2026-87107-hashicorp-consul-authorization-bypass-in-catalog-deregistration"},{"cve":"CVE-2026-87106","cvss":6.5,"epss":0.0041,"slug":"cve-2026-87106-hashicorp-consul-denial-of-service-in-native-rpc-listener","title":"HashiCorp Consul denial of service in native RPC listener","severity":"medium","exploited":false,"published_at":"2026-09-10T19:17:37.293+00:00","url":"https://junglewise.ai/threats/cve-2026-87106-hashicorp-consul-denial-of-service-in-native-rpc-listener"},{"cve":"CVE-2026-87090","cvss":8.3,"epss":0.0037,"slug":"cve-2026-87090-hashicorp-consul-authorization-bypass-in-catalog-node-write","title":"HashiCorp Consul authorization bypass in catalog node-write","severity":"high","exploited":false,"published_at":"2026-09-10T19:17:37.157+00:00","url":"https://junglewise.ai/threats/cve-2026-87090-hashicorp-consul-authorization-bypass-in-catalog-node-write"},{"cve":"CVE-2026-5006","cvss":6.8,"epss":0.0028,"slug":"cve-2026-5006-hashicorp-vault-privilege-escalation-in-templated-policy-paths","title":"HashiCorp Vault privilege escalation in templated policy paths","severity":"medium","exploited":false,"published_at":"2026-08-24T21:17:46.147+00:00","url":"https://junglewise.ai/threats/cve-2026-5006-hashicorp-vault-privilege-escalation-in-templated-policy-paths"},{"cve":"CVE-2026-12624","cvss":4.3,"epss":0.0027,"slug":"cve-2026-12624-hashicorp-vault-acl-policy-engine-authorization-bypass-in-list","title":"HashiCorp Vault ACL policy engine authorization bypass in LIST requests","severity":"medium","exploited":false,"published_at":"2026-08-10T17:17:29.293+00:00","url":"https://junglewise.ai/threats/cve-2026-12624-hashicorp-vault-acl-policy-engine-authorization-bypass-in-list"},{"cve":"CVE-2026-16328","cvss":8.6,"slug":"cve-2026-16328-hashicorp-consul-mcp-server-ssrf-and-token-exfiltration","title":"HashiCorp consul-mcp-server SSRF and token exfiltration","severity":"high","exploited":false,"published_at":"2026-07-29T19:16:45.06+00:00","url":"https://junglewise.ai/threats/cve-2026-16328-hashicorp-consul-mcp-server-ssrf-and-token-exfiltration"},{"cve":"CVE-2026-16326","cvss":10,"slug":"cve-2026-16326-hashicorp-consul-mcp-server-session-state-leakage-in-stateless","title":"HashiCorp consul-mcp-server session state leakage in stateless mode","severity":"critical","exploited":false,"published_at":"2026-07-29T19:16:44.9+00:00","url":"https://junglewise.ai/threats/cve-2026-16326-hashicorp-consul-mcp-server-session-state-leakage-in-stateless"},{"cve":"CVE-2026-16498","cvss":10,"slug":"cve-2026-16498-hashicorp-terraform-mcp-server-cross-tenant-credential-reuse-in","title":"HashiCorp terraform-mcp-server cross-tenant credential reuse in stateless mode","severity":"critical","exploited":false,"published_at":"2026-07-28T19:17:32.117+00:00","url":"https://junglewise.ai/threats/cve-2026-16498-hashicorp-terraform-mcp-server-cross-tenant-credential-reuse-in"},{"cve":"CVE-2026-16496","cvss":8.9,"slug":"cve-2026-16496-hashicorp-terraform-mcp-server-auth-bypass-in-stateful-transport","title":"HashiCorp terraform-mcp-server auth bypass in stateful transport mode","severity":"high","exploited":false,"published_at":"2026-07-28T19:17:31.983+00:00","url":"https://junglewise.ai/threats/cve-2026-16496-hashicorp-terraform-mcp-server-auth-bypass-in-stateful-transport"},{"cve":"CVE-2026-14869","cvss":8.6,"slug":"cve-2026-14869-hashicorp-terraform-mcp-server-ssrf-in-streamable-http-transport","title":"HashiCorp terraform-mcp-server SSRF in streamable-HTTP transport","severity":"high","exploited":false,"published_at":"2026-07-28T19:17:31.423+00:00","url":"https://junglewise.ai/threats/cve-2026-14869-hashicorp-terraform-mcp-server-ssrf-in-streamable-http-transport"},{"cve":"CVE-2026-14896","cvss":4.2,"slug":"cve-2026-14896-hashicorp-nomad-authorization-bypass-in-dynamic-host-volumes","title":"HashiCorp Nomad authorization bypass in dynamic host volumes","severity":"medium","exploited":false,"published_at":"2026-07-08T21:16:47.03+00:00","url":"https://junglewise.ai/threats/cve-2026-14896-hashicorp-nomad-authorization-bypass-in-dynamic-host-volumes"},{"cve":"CVE-2026-14891","cvss":8.7,"slug":"cve-2026-14891-hashicorp-nomad-sandbox-escape-in-docker-task-driver","title":"HashiCorp Nomad sandbox escape in Docker task driver","severity":"high","exploited":false,"published_at":"2026-07-08T20:16:48.3+00:00","url":"https://junglewise.ai/threats/cve-2026-14891-hashicorp-nomad-sandbox-escape-in-docker-task-driver"},{"cve":"CVE-2026-14373","cvss":7.7,"slug":"cve-2026-14373-hashicorp-nomad-authorization-bypass-in-docker-task-driver-host","title":"HashiCorp Nomad authorization bypass in Docker task driver host namespaces","severity":"high","exploited":false,"published_at":"2026-07-08T20:16:48.08+00:00","url":"https://junglewise.ai/threats/cve-2026-14373-hashicorp-nomad-authorization-bypass-in-docker-task-driver-host"},{"cve":"CVE-2026-14361","cvss":4.7,"slug":"cve-2026-14361-hashicorp-consul-template-path-redirection-in-writetofile-helper","title":"HashiCorp Consul-template path redirection in writeToFile helper","severity":"medium","exploited":false,"published_at":"2026-07-08T20:16:47.85+00:00","url":"https://junglewise.ai/threats/cve-2026-14361-hashicorp-consul-template-path-redirection-in-writetofile-helper"},{"cve":"CVE-2026-14362","cvss":4.9,"slug":"cve-2026-14362-hashicorp-memberlist-denial-of-service-in-push-pull-state","title":"HashiCorp memberlist denial of service in push/pull state handling","severity":"medium","exploited":false,"published_at":"2026-07-08T18:16:32.13+00:00","url":"https://junglewise.ai/threats/cve-2026-14362-hashicorp-memberlist-denial-of-service-in-push-pull-state"},{"cve":"CVE-2026-14468","cvss":7.7,"slug":"cve-2026-14468-hashicorp-terraform-enterprise-path-traversal-in-vcs-module","title":"HashiCorp Terraform Enterprise path traversal in VCS module ingestion","severity":"high","exploited":false,"published_at":"2026-07-06T21:16:53+00:00","url":"https://junglewise.ai/threats/cve-2026-14468-hashicorp-terraform-enterprise-path-traversal-in-vcs-module"},{"cve":"CVE-2026-5051","cvss":4.4,"slug":"cve-2026-5051-hashicorp-vault-path-traversal-in-audit-device-validation","title":"HashiCorp Vault path traversal in audit device validation","severity":"medium","exploited":false,"published_at":"2026-07-01T18:16:36.227+00:00","url":"https://junglewise.ai/threats/cve-2026-5051-hashicorp-vault-path-traversal-in-audit-device-validation"},{"cve":"CVE-2026-8052","cvss":6,"epss":0.0003,"slug":"cve-2026-8052-hashicorp-nomad-exec2-task-driver-symlink-attack-in-log-handling","title":"HashiCorp Nomad exec2 task driver symlink attack in log handling","severity":"medium","exploited":false,"published_at":"2026-05-12T20:16:46.72+00:00","url":"https://junglewise.ai/threats/cve-2026-8052-hashicorp-nomad-exec2-task-driver-symlink-attack-in-log-handling"},{"cve":"CVE-2026-7474","cvss":8.8,"epss":0.0066,"slug":"cve-2026-7474-hashicorp-nomad-path-traversal-in-dynamic-host-volumes","title":"HashiCorp Nomad path traversal in Dynamic Host Volumes","severity":"high","exploited":false,"published_at":"2026-05-12T20:16:46.38+00:00","url":"https://junglewise.ai/threats/cve-2026-7474-hashicorp-nomad-path-traversal-in-dynamic-host-volumes"},{"cve":"CVE-2026-6959","cvss":6,"epss":0.0017,"slug":"cve-2026-6959-hashicorp-nomad-arbitrary-file-read-and-write-via-symlink-attack","title":"HashiCorp Nomad arbitrary file read and write via symlink attack","severity":"medium","exploited":false,"published_at":"2026-05-12T20:16:46.267+00:00","url":"https://junglewise.ai/threats/cve-2026-6959-hashicorp-nomad-arbitrary-file-read-and-write-via-symlink-attack"},{"cve":"CVE-2026-5061","cvss":4.7,"slug":"cve-2026-5061-hashicorp-consul-template-sandbox-path-bypass-in-file-helper","title":"HashiCorp consul-template sandbox path bypass in file helper","severity":"medium","exploited":false,"published_at":"2026-05-12T15:16:16.343+00:00","url":"https://junglewise.ai/threats/cve-2026-5061-hashicorp-consul-template-sandbox-path-bypass-in-file-helper"},{"cve":"CVE-2026-7776","cvss":7.5,"epss":0.0034,"slug":"cve-2026-7776-hashicorp-boundary-denial-of-service-in-worker-node-enrollment","title":"HashiCorp Boundary denial of service in worker node enrollment","severity":"high","exploited":false,"published_at":"2026-05-05T00:30:22+00:00","url":"https://junglewise.ai/threats/cve-2026-7776-hashicorp-boundary-denial-of-service-in-worker-node-enrollment"}],"vendor":{"hub":true,"name":"HashiCorp","slug":"hashicorp","homepage":"https://www.hashicorp.com/","description":"A software company that provides open-source tools and commercial products for cloud infrastructure automation and management.","url":"https://junglewise.ai/threats/vendors/hashicorp"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":6},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":2,"exploited":0,"vulnerabilities":5},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":5},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2026-16326","cvss":10,"slug":"cve-2026-16326-hashicorp-consul-mcp-server-session-state-leakage-in-stateless","title":"HashiCorp consul-mcp-server session state leakage in stateless mode","severity":"critical","exploited":false,"published_at":"2026-07-29T19:16:44.9+00:00","url":"https://junglewise.ai/threats/cve-2026-16326-hashicorp-consul-mcp-server-session-state-leakage-in-stateless"},{"cve":"CVE-2026-16498","cvss":10,"slug":"cve-2026-16498-hashicorp-terraform-mcp-server-cross-tenant-credential-reuse-in","title":"HashiCorp terraform-mcp-server cross-tenant credential reuse in stateless mode","severity":"critical","exploited":false,"published_at":"2026-07-28T19:17:32.117+00:00","url":"https://junglewise.ai/threats/cve-2026-16498-hashicorp-terraform-mcp-server-cross-tenant-credential-reuse-in"},{"cve":"CVE-2026-16496","cvss":8.9,"slug":"cve-2026-16496-hashicorp-terraform-mcp-server-auth-bypass-in-stateful-transport","title":"HashiCorp terraform-mcp-server auth bypass in stateful transport mode","severity":"high","exploited":false,"published_at":"2026-07-28T19:17:31.983+00:00","url":"https://junglewise.ai/threats/cve-2026-16496-hashicorp-terraform-mcp-server-auth-bypass-in-stateful-transport"},{"cve":"CVE-2026-7474","cvss":8.8,"epss":0.0066,"slug":"cve-2026-7474-hashicorp-nomad-path-traversal-in-dynamic-host-volumes","title":"HashiCorp Nomad path traversal in Dynamic Host Volumes","severity":"high","exploited":false,"published_at":"2026-05-12T20:16:46.38+00:00","url":"https://junglewise.ai/threats/cve-2026-7474-hashicorp-nomad-path-traversal-in-dynamic-host-volumes"},{"cve":"CVE-2026-14891","cvss":8.7,"slug":"cve-2026-14891-hashicorp-nomad-sandbox-escape-in-docker-task-driver","title":"HashiCorp Nomad sandbox escape in Docker task driver","severity":"high","exploited":false,"published_at":"2026-07-08T20:16:48.3+00:00","url":"https://junglewise.ai/threats/cve-2026-14891-hashicorp-nomad-sandbox-escape-in-docker-task-driver"},{"cve":"CVE-2026-16328","cvss":8.6,"slug":"cve-2026-16328-hashicorp-consul-mcp-server-ssrf-and-token-exfiltration","title":"HashiCorp consul-mcp-server SSRF and token exfiltration","severity":"high","exploited":false,"published_at":"2026-07-29T19:16:45.06+00:00","url":"https://junglewise.ai/threats/cve-2026-16328-hashicorp-consul-mcp-server-ssrf-and-token-exfiltration"},{"cve":"CVE-2026-14869","cvss":8.6,"slug":"cve-2026-14869-hashicorp-terraform-mcp-server-ssrf-in-streamable-http-transport","title":"HashiCorp terraform-mcp-server SSRF in streamable-HTTP transport","severity":"high","exploited":false,"published_at":"2026-07-28T19:17:31.423+00:00","url":"https://junglewise.ai/threats/cve-2026-14869-hashicorp-terraform-mcp-server-ssrf-in-streamable-http-transport"},{"cve":"CVE-2026-87090","cvss":8.3,"epss":0.0037,"slug":"cve-2026-87090-hashicorp-consul-authorization-bypass-in-catalog-node-write","title":"HashiCorp Consul authorization bypass in catalog node-write","severity":"high","exploited":false,"published_at":"2026-09-10T19:17:37.157+00:00","url":"https://junglewise.ai/threats/cve-2026-87090-hashicorp-consul-authorization-bypass-in-catalog-node-write"},{"cve":"CVE-2026-3605","cvss":8.1,"epss":0.005,"slug":"cve-2026-3605-hashicorp-vault-policy-bypass-in-kvv2-secrets-engine","title":"HashiCorp Vault policy bypass in KVv2 secrets engine","severity":"high","exploited":false,"published_at":"2026-04-17T04:16:03.263+00:00","url":"https://junglewise.ai/threats/cve-2026-3605-hashicorp-vault-policy-bypass-in-kvv2-secrets-engine"},{"cve":"CVE-2026-87993","cvss":7.7,"epss":0.0038,"slug":"cve-2026-87993-hashicorp-consul-template-information-disclosure-in-error","title":"HashiCorp Consul-template information disclosure in error handling","severity":"high","exploited":false,"published_at":"2026-09-10T19:17:39.13+00:00","url":"https://junglewise.ai/threats/cve-2026-87993-hashicorp-consul-template-information-disclosure-in-error"}],"generated_at":"2026-09-26T15:07:00.181821+00:00","technologies":[{"name":"HashiCorp Vault","slug":"vault","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/vault"},{"name":"HashiCorp Vault Enterprise","slug":"vault-enterprise","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/vault-enterprise"},{"name":"HashiCorp Nomad","slug":"nomad","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/nomad"},{"name":"HashiCorp Consul","slug":"consul","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/consul"},{"name":"HashiCorp Nomad Enterprise","slug":"nomad-enterprise","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/nomad-enterprise"},{"name":"HashiCorp Consul Enterprise","slug":"consul-enterprise","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/consul-enterprise"},{"name":"HashiCorp Consul-Template","slug":"consul-template","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/consul-template"},{"name":"HashiCorp Terraform MCP Server","slug":"terraform-mcp-server","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/terraform-mcp-server"}]}