Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4309 articles · 196689 vulns · 37/41 feeds (7d)
← Back to list
8.2
CVE-2026-14886PATCHED
hashi · vault enterpri

Vault Enterprise vulnerable to cross-namespace entity deletion

Description

Vault Enterprise's identity entity batch-delete endpoint is vulnerable to a cross-namespace authorization bypass that may allow an authenticated caller in one namespace to permanently delete the storage backing of entities belonging to another namespace. This vulnerability (CVE-2026-14886) is fixed in Vault Enterprise 2.0.4, 1.21.9, 1.20.14 and 1.19.20.

Affected Products

VendorProductVersions
hashivault enterpri2.0.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
hashivaultcert_advisory90%

References

  • https://discuss.hashicorp.com/t/hcsec-2026-27-vault-enterprise-vulnerable-to-cross-namespace-entity-deletion/77634

Related News (2 articles)

Tier B
BSI Advisories13d ago
[NEU] [hoch] Hashicorp Vault und Vault Enterprise: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB14d ago
CVE-2026-14886 | HashiCorp Vault Enterprise up to 2.0.3/1.21.8/1.20.13/1.19.19 Identity Entity Batch-Delete Endpoint authorization
→ No new info (linked only)
CVSS 3.18.2 HIGH
VectorCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
2.0.4
CWECWE-862
PublishedAug 10, 2026
Trending Score9
Source articles2
Independent2
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

MEDIUMCVE-2026-14978
Unicode normalization mismatch in go-slug ignore pattern matching may bypass intended file exclusions
Trending: 33
CRITICALCVE-2026-16498
terraform-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless mode
Trending: 13
HIGHCVE-2026-14869
terraform-mcp-server vulnerable to server side request forgery leading to token exposure
Trending: 11
HIGHCVE-2026-16496
terraform-mcp-server vulnerable to cross-user credential inheritance if an MCP session ID is obtained by another user
Trending: 10
HIGHCVE-2026-19589
Packer vulnerable to arbitrary file write via crafted plugin archive during installation
Trending: 9

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 10, 2026
Discovered by ZDM
Aug 10, 2026
Patch Available
Aug 12, 2026