Impact
Vault’s ACL policy cache incorrectly handles policy names that contain path traversal characters, allowing a token to reference policies defined in other namespaces, including the root namespace. This flaw effectively lets an attacker gain the permissions of a target namespace by supplying a crafted policy name when creating or assigning tokens, constituting an unauthorized privilege escalation. The weakness is a classic Path Traversal error (CWE‑22).
Affected Systems
The issue affects HashiCorp Vault Enterprise deployments but does not impact the Community Edition, which has no namespace support. The vulnerability is fixed in Vault Enterprise releases 2.1.2, 1.21.12, 1.20.17, and 1.19.23; older releases remain vulnerable.
Risk and Exploitability
The CVSS score is 5.4, indicating a moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation. The most likely attack vector is an internal or compromised user with the capability to create or modify tokens, who can embed path traversal patterns in policy names to hijack access across namespaces.
OpenCVE Enrichment