AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-12624

MEDIUM · CVSS 4.3 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-08-10 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The vulnerability affects the ACL policy engine in Vault, where a wildcard deny rule may not be properly enforced against LIST requests with a trailing slash, potentially allowing unauthorized enumeration of entries in restricted paths. This could lead to exposure of sensitive information for tokens that should be denied access. Organizations using affected versions of Vault should prioritize this issue to mitigate the risk of unauthorized data access.

CVE
CVE-2026-12624
Severity
MEDIUM
CVSS
4.3
EPSS
0.20%

Original NVD Description

Vault’s ACL policy engine did not consistently enforce a wildcard (glob) deny rule against LIST requests made with a trailing slash on the denied path. This may allow a token holding a broader allow rule alongside a narrower wildcard deny rule to enumerate the names of entries beneath a path it was intended to be denied access to. This vulnerability (CVE-2026-12624) is fixed in Vault Community Edition 2.0.3 and Vault Enterprise 2.0.3, 1.21.8, 1.20.13, and 1.19.19.