HashiCorp security advisory (AV26-797)
Serial Number: AV26-797 Date: August 11, 2026 As of August 10, 2026, HashiCorp is affected by vulnerabilities in the following products: Vault Prior to 2.0.3 Vault Enterprise multiple versions The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. HCSEC-2026-27 - Vault Enterprise vulnerable to cross-namespace entity deletion - Security - HashiCorp Discuss Security - HashiCorp Discuss
CSIRTS triage
- What
- Vault Enterprise is vulnerable to cross-namespace entity deletion, which can lead to unauthorized modification of authentication and authorization configurations.
- Who is affected
- HashiCorp Vault deployments, particularly multi-tenant or namespace-enabled Vault Enterprise instances.
- Urgency
- High urgency; the ability to delete entities across namespace boundaries undermines identity and access control isolation.
- Action
- Upgrade Vault to version 2.0.3 or apply patches to affected Vault Enterprise versions as recommended by HashiCorp.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Vault
Get an email when a new Vault advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/hashicorp-security-advisory-av26-797
More from Canadian Centre for Cyber Security
- unknownWatchGuard security advisory (AV26-847)2026-08-25
- unknownOpenSSL security advisory (AV26-846)2026-08-25
- unknownGitea security advisory (AV26-845)2026-08-25
- unknownGoogle security advisory (AV26-844)2026-08-24
- criticalOracle security advisory – January 2026 quarterly rollup (AV26-042) – Update 22026-08-24