PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-89322 HashiCorp CVE debrief

HashiCorp Vault and Vault Enterprise have a vulnerability allowing an authenticated user with delegated permissions to bypass explicit deny restrictions, potentially leading to privilege escalation. This issue is fixed in Vault Community Edition 2.1.2 and Vault Enterprise 2.1.2, 1.21.12, 1.20.17, and 1.19.23. The vulnerability occurs due to inconsistent evaluation of ACL policies against the canonical form of resource and policy names. Defenders should prioritize verifying and applying patches, reviewing and updating ACL policies, and monitoring for suspicious activity.

Vendor
HashiCorp
Product
Vault
CVSS
HIGH 7.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Defenders responsible for Vault and Vault Enterprise instances, especially those with delegated permissions or sensitive resource access, should assess exposure and prioritize patching.

Why it matters

CVE-2026-89322 allows an authenticated user with delegated permissions to bypass explicit deny restrictions in Vault and Vault Enterprise, potentially leading to privilege escalation. Defenders should prioritize verifying and applying patches, reviewing and updating ACL policies, and monitoring for suspicious activity.

  • Verification of patch application is required to prevent potential privilege escalation.
  • Review and update of ACL policies is necessary to ensure explicit deny restrictions are enforced.
  • Monitoring for suspicious activity related to delegated permissions is recommended.

Technical summary

The vulnerability occurs due to inconsistent evaluation of ACL policies against the canonical form of resource and policy names in Vault and Vault Enterprise. This allows an authenticated user with delegated permissions to bypass an explicit deny restriction and access a protected resource or assign a denied policy, potentially leading to privilege escalation. The issue is fixed in Vault Community Edition 2.1.2 and Vault Enterprise 2.1.2, 1.21.12, 1.20.17, and 1.19.23. Defenders should prioritize verifying and applying patches, reviewing and updating ACL policies, and monitoring for suspicious activity.

Defensive priority

Defenders should prioritize verifying and applying patches for Vault and Vault Enterprise instances, especially those with delegated permissions or sensitive resource access.

Recommended defensive actions

  • Verify and apply patches for Vault and Vault Enterprise instances
  • Review and update ACL policies to ensure explicit deny restrictions are enforced
  • Monitor for suspicious activity related to delegated permissions
  • Perform thorough vulnerability assessments
  • Implement additional security measures
  • Conduct regular security audits
  • Review and update incident response plans

Evidence notes

The CVE record and source item provide details on the vulnerability, affected versions, and fixed versions. However, limited information is available on potential exploitation or victim impact. The vulnerability allows an authenticated user with delegated permissions to bypass an explicit deny restriction and access a protected resource or assign a denied policy, potentially leading to privilege escalation. Defenders should verify patch application, review and update ACL policies, and monitor for suspicious activity related to the CVE

Sources and references

Verified primary and authoritative sources

  • CVE-2026-89322 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-89322

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-89322 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-89322

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Vault ACL Policy Evaluation May Allow Bypass of Deny Restrictions

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/89xxx/CVE-2026-89322.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://discuss.hashicorp.com/t/hcsec-2026-43-vault-inconsistent-acl-policy-evaluation-may-allow-bypass-of-deny-restrictions/77815

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.