CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

HashiCorp security advisory (AV26-797)

unknown
Serial Number: AV26-797 Date: August 11, 2026 As of August 10, 2026, HashiCorp is affected by vulnerabilities in the following products: Vault Prior to 2.0.3 Vault Enterprise multiple versions The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. HCSEC-2026-27 - Vault Enterprise vulnerable to cross-namespace entity deletion - Security - HashiCorp Discuss Security - HashiCorp Discuss

CSIRTS triage

vendor: HashiCorpproduct: VaultAuthentication bypassaffected: Prior to 2.0.3 and multiple Vault Enterprise versions
What
Vault Enterprise is vulnerable to cross-namespace entity deletion, which can lead to unauthorized modification of authentication and authorization configurations.
Who is affected
HashiCorp Vault deployments, particularly multi-tenant or namespace-enabled Vault Enterprise instances.
Urgency
High urgency; the ability to delete entities across namespace boundaries undermines identity and access control isolation.
Action
Upgrade Vault to version 2.0.3 or apply patches to affected Vault Enterprise versions as recommended by HashiCorp.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Vault

Get an email when a new Vault advisory drops — max one per day, one-click unsubscribe.

Details

Source
Canadian Centre for Cyber Security (CA · national-cert · site)
Severity
unknown
Published
2026-08-11
Exploitation
Not in CISA KEV at last sync

Original advisory: https://cyber.gc.ca/en/alerts-advisories/hashicorp-security-advisory-av26-797

More from Canadian Centre for Cyber Security