AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-14886

HIGH · CVSS 8.2 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-08-10 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The vulnerability in Vault Enterprise allows an authenticated user to exploit the identity entity batch-delete endpoint, enabling them to delete entities across different namespaces without proper authorization. This could lead to significant data loss and integrity issues for organizations using the affected versions. Organizations utilizing Vault Enterprise should prioritize this issue and upgrade to the patched versions (2.0.4, 1.21.9, 1.20.14, or 1.19.20) to mitigate the risk.

CVE
CVE-2026-14886
Severity
HIGH
CVSS
8.2
EPSS
0.24%

Original NVD Description

Vault Enterprise's identity entity batch-delete endpoint is vulnerable to a cross-namespace authorization bypass that may allow an authenticated caller in one namespace to permanently delete the storage backing of entities belonging to another namespace. This vulnerability (CVE-2026-14886) is fixed in Vault Enterprise 2.0.4, 1.21.9, 1.20.14 and 1.19.20.