Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2600 articles · 111476 vulns · 36/41 feeds (7d)
← Back to list
EST
PRE-CVE
hashi · vault community edition and vault enterprise edition

Vault KVv2 Metadata and Secret Deletion Policy Bypass and Server-Side Request Forgery Vulnerabilities

72% confidence

Description

Multiple vulnerabilities in HashiCorp Vault Community and Enterprise Editions including KVv2 metadata and secret deletion policy bypass leading to denial-of-service, and server-side request forgery in ACME challenge validation via attacker-controlled DNS.

Affected Products

VendorProductVersions
hashivault community edition and vault enterprise editionmultiple versions

Related News (1 articles)

Tier B
CCCS Canada2h ago
HashiCorp security advisory (AV26-363)
→ No new info (linked only)
CISA KEV❌ No
Actively exploited❌ No
PublishedApr 17, 2026
Last enriched2h ago
Tags
denial-of-serviceserver-side request forgerypolicy bypass
Trending Score20
Source articles1
Independent1
Info Completeness5/14
Missing: cve_id, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-4525EXP
Vault Token Leaked to Backends via Authorization: Bearer Passthrough Header
Trending: 49
HIGHCVE-2026-3605EXP
Vault KVv2 Metadata and Secret Deletion Policy Bypass Denial-of-Service
Trending: 49
MEDIUMCVE-2026-5052
Vault Vulnerable to Server-Side Request Forgery in ACME Challenge Validation via Attacker-Controlled DNS
Trending: 44
HIGHCVE-2026-5807
Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations
Trending: 36
HIGHCVE-2026-4660
Go-getter may allow to arbitrary filesystem reads through git operations
Trending: 9

Pin to Dashboard

Verification

State: reported
Confidence: 72%

Vulnerability Timeline

CVE Published
Apr 17, 2026
Discovered by ZDM
Apr 17, 2026