PatchSiren cyber security CVE debrief
CVE-2026-89322 HashiCorp CVE debrief
HashiCorp Vault and Vault Enterprise have a vulnerability allowing an authenticated user with delegated permissions to bypass explicit deny restrictions, potentially leading to privilege escalation. This issue is fixed in Vault Community Edition 2.1.2 and Vault Enterprise 2.1.2, 1.21.12, 1.20.17, and 1.19.23. The vulnerability occurs due to inconsistent evaluation of ACL policies against the canonical form of resource and policy names. Defenders should prioritize verifying and applying patches, reviewing and updating ACL policies, and monitoring for suspicious activity.
- Vendor
- HashiCorp
- Product
- Vault
- CVSS
- HIGH 7.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Defenders responsible for Vault and Vault Enterprise instances, especially those with delegated permissions or sensitive resource access, should assess exposure and prioritize patching.
Why it matters
CVE-2026-89322 allows an authenticated user with delegated permissions to bypass explicit deny restrictions in Vault and Vault Enterprise, potentially leading to privilege escalation. Defenders should prioritize verifying and applying patches, reviewing and updating ACL policies, and monitoring for suspicious activity.
- Verification of patch application is required to prevent potential privilege escalation.
- Review and update of ACL policies is necessary to ensure explicit deny restrictions are enforced.
- Monitoring for suspicious activity related to delegated permissions is recommended.
Technical summary
The vulnerability occurs due to inconsistent evaluation of ACL policies against the canonical form of resource and policy names in Vault and Vault Enterprise. This allows an authenticated user with delegated permissions to bypass an explicit deny restriction and access a protected resource or assign a denied policy, potentially leading to privilege escalation. The issue is fixed in Vault Community Edition 2.1.2 and Vault Enterprise 2.1.2, 1.21.12, 1.20.17, and 1.19.23. Defenders should prioritize verifying and applying patches, reviewing and updating ACL policies, and monitoring for suspicious activity.
Defensive priority
Defenders should prioritize verifying and applying patches for Vault and Vault Enterprise instances, especially those with delegated permissions or sensitive resource access.
Recommended defensive actions
- Verify and apply patches for Vault and Vault Enterprise instances
- Review and update ACL policies to ensure explicit deny restrictions are enforced
- Monitor for suspicious activity related to delegated permissions
- Perform thorough vulnerability assessments
- Implement additional security measures
- Conduct regular security audits
- Review and update incident response plans
Evidence notes
The CVE record and source item provide details on the vulnerability, affected versions, and fixed versions. However, limited information is available on potential exploitation or victim impact. The vulnerability allows an authenticated user with delegated permissions to bypass an explicit deny restriction and access a protected resource or assign a denied policy, potentially leading to privilege escalation. Defenders should verify patch application, review and update ACL policies, and monitor for suspicious activity related to the CVE
Sources and references
Verified primary and authoritative sources
-
CVE-2026-89322 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-89322
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-89322 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-89322
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Vault ACL Policy Evaluation May Allow Bypass of Deny Restrictions
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/89xxx/CVE-2026-89322.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://discuss.hashicorp.com/t/hcsec-2026-43-vault-inconsistent-acl-policy-evaluation-may-allow-bypass-of-deny-restrictions/77815
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.