CVE-2026-14886: Vault Enterprise vulnerable to cross-namespace entity deletion
Vault Enterprise's identity entity batch-delete endpoint is vulnerable to a cross-namespace authorization bypass that may allow an authenticated caller in one namespace to permanently delete the storage backing of entities belonging to another namespace. This vulnerability (CVE-2026-14886) is fixed in Vault Enterprise 2.0.4, 1.21.9, 1.20.14 and 1.19.20.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Vault Enterpriseto a version that resolves this vulnerability.Fixed in 2.0.4 - Upgrade
Upgrade
Vault Enterpriseto a version that resolves this vulnerability.Fixed in 1.21.9 - Upgrade
Upgrade
Vault Enterpriseto a version that resolves this vulnerability.Fixed in 1.20.14 - Upgrade
Upgrade
Vault Enterpriseto a version that resolves this vulnerability.Fixed in 1.19.20
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14886?
CVE-2026-14886 has a high severity rating of 8.2.
How do I fix CVE-2026-14886?
To fix CVE-2026-14886, update to the latest version of HashiCorp Vault Enterprise where the vulnerability has been addressed.
What kind of vulnerability is CVE-2026-14886?
CVE-2026-14886 is a cross-namespace authorization bypass vulnerability that affects Vault Enterprise.
Who is affected by CVE-2026-14886?
Authenticated users in one namespace may be able to delete entities in another namespace due to CVE-2026-14886.
What is the impact of CVE-2026-14886?
The impact of CVE-2026-14886 includes the potential for permanent deletion of entity storage across different namespaces.