CyberRota Analysis
AI-GeneratedThe vulnerability affects the ACL policy engine in Vault, where a wildcard deny rule may not be properly enforced against LIST requests with a trailing slash, potentially allowing unauthorized enumeration of entries in restricted paths. This could lead to exposure of sensitive information for tokens that should be denied access. Organizations using affected versions of Vault should prioritize this issue to mitigate the risk of unauthorized data access.
Original NVD Description
Vault’s ACL policy engine did not consistently enforce a wildcard (glob) deny rule against LIST requests made with a trailing slash on the denied path. This may allow a token holding a broader allow rule alongside a narrower wildcard deny rule to enumerate the names of entries beneath a path it was intended to be denied access to. This vulnerability (CVE-2026-12624) is fixed in Vault Community Edition 2.0.3 and Vault Enterprise 2.0.3, 1.21.8, 1.20.13, and 1.19.19.