Vault Enterprise NS Auth Bypass via Batch-Delete (pre-2.0.4/1.21.9)
CVE-2026-14886 Published on August 10, 2026

Vault Enterprise vulnerable to cross-namespace entity deletion
Vault Enterprise's identity entity batch-delete endpoint is vulnerable to a cross-namespace authorization bypass that may allow an authenticated caller in one namespace to permanently delete the storage backing of entities belonging to another namespace. This vulnerability (CVE-2026-14886) is fixed in Vault Enterprise 2.0.4, 1.21.9, 1.20.14 and 1.19.20.

NVD

Weakness Type

What is an AuthZ Vulnerability?

The software does not perform an authorization check when an actor attempts to access a resource or perform an action.

CVE-2026-14886 has been classified to as an AuthZ vulnerability or weakness.


Products Associated with CVE-2026-14886

Want to know whenever a new CVE is published for HashiCorp Vault? stack.watch will email you.

 

Affected Versions

HashiCorp Vault Enterprise: