CyberRota Analysis
AI-GeneratedThe vulnerability in Vault Enterprise allows an authenticated user to exploit the identity entity batch-delete endpoint, enabling them to delete entities across different namespaces without proper authorization. This could lead to significant data loss and integrity issues for organizations using the affected versions. Organizations utilizing Vault Enterprise should prioritize this issue and upgrade to the patched versions (2.0.4, 1.21.9, 1.20.14, or 1.19.20) to mitigate the risk.
Original NVD Description
Vault Enterprise's identity entity batch-delete endpoint is vulnerable to a cross-namespace authorization bypass that may allow an authenticated caller in one namespace to permanently delete the storage backing of entities belonging to another namespace. This vulnerability (CVE-2026-14886) is fixed in Vault Enterprise 2.0.4, 1.21.9, 1.20.14 and 1.19.20.