CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-14886

highCVSS 8.2covered by 2 sourcesfirst seen 2026-08-10
A remote authenticated attacker can exploit multiple vulnerabilities in Hashicorp Vault and Vault Enterprise to disclose information, bypass authorization mechanisms, and manipulate data.

CSIRTS triage

What
Remote authenticated attacker can disclose information, bypass authorization mechanisms, and manipulate data in Hashicorp Vault and Vault Enterprise.
Who is affected
All Vault and Vault Enterprise deployments are affected.
Urgency
High; affects critical secrets management infrastructure and authorization controls.
Action
Apply security patches for CVE-2026-12624 and CVE-2026-14886 to Vault immediately.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-14886

Get an email if CVE-2026-14886 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-14886

CVE.org record

Embed the live status

CVE-2026-14886 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-14886 status](https://www.csirts.com/badge/CVE-2026-14886)](https://www.csirts.com/cve/CVE-2026-14886)