An authenticated user with access to a kvv2 path through a policy containing a glob may be able to delete secrets they were not authorized to read or write, resulting in denial-of-service. This vulnerability did not allow a malicious user to delete secrets across namespaces, nor read any secret data. Fxed in Vault Community Edition 2.0.0 and Vault Enterprise 2.0.0, 1.21.5, 1.20.10, and 1.19.16.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 17 Apr 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hashicorp
Hashicorp vault Hashicorp vault Enterprise |
|
| Vendors & Products |
Hashicorp
Hashicorp vault Hashicorp vault Enterprise |
Fri, 17 Apr 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authenticated user with access to a kvv2 path through a policy containing a glob may be able to delete secrets they were not authorized to read or write, resulting in denial-of-service. This vulnerability did not allow a malicious user to delete secrets across namespaces, nor read any secret data. Fxed in Vault Community Edition 2.0.0 and Vault Enterprise 2.0.0, 1.21.5, 1.20.10, and 1.19.16. | |
| Title | Vault KVv2 Metadata and Secret Deletion Policy Bypass Denial-of-Service | |
| Weaknesses | CWE-288 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: HashiCorp
Published:
Updated: 2026-04-17T02:44:42.032Z
Reserved: 2026-03-05T16:37:23.520Z
Link: CVE-2026-3605
No data.
Status : Received
Published: 2026-04-17T04:16:03.263
Modified: 2026-04-17T04:16:03.263
Link: CVE-2026-3605
No data.
OpenCVE Enrichment
Updated: 2026-04-17T05:00:05Z
Weaknesses