CVE-2026-3605
An authenticated user with access to a kvv2 path through a policy containing a glob may be able to delete secrets they were not authorized to read or write, resulting in denial-of-service. This vulnerability did not allow a malicious user to delete secrets across namespaces, nor read any secret data. Fxed in Vault Community Edition 2.0.0 and Vault Enterprise 2.0.0, 1.21.5, 1.20.10, and 1.19.16.
Published:Apr 17, 2026
Last Modified:Apr 25, 2026
EPS:Apr 17, 2026
EPSS Score:0.00014
CVSS Score:8.1
Affected Products
Vendor
Product
Action
Vendor
Hashicorp
Product
Vault
Hashicorp
Vault
Vendor
Hashicorp
Product
Vault Enterprise
Hashicorp
Vault Enterprise
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
