Impact
HashiCorp Vault Enterprise's identity entity batch-delete endpoint supports deleting multiple entities in a single request. However, the implementation does not correctly enforce namespace boundaries, enabling an authenticated caller in one namespace to delete the storage backing of entities belonging to another namespace. This vulnerability, classified as a weakness in authorization (CWE-862), can result in permanent removal of sensitive data and configuration from a protected namespace.
Affected Systems
The affected product is HashiCorp Vault Enterprise. Versions prior to the release of 2.0.4, 1.21.9, 1.20.14, and 1.19.20 contain the flaw. Any deployment running an earlier revision is vulnerable and must be upgraded to one of the fixed releases or a later version.
Risk and Exploitability
The CVSS score of 8.2 indicates high severity, with exploitation requiring an authenticated user that possesses deletion privileges within one namespace. The exact EPSS score is not available, but the absence from the KEV catalog means no known public exploits have been reported to date. Nevertheless, the cross-namespace authorization bypass allows a malicious actor to target arbitrary entities in another namespace, thereby causing significant data loss. The risk is elevated for environments where multiple namespaces coexist and user accounts are granted broad deletion rights. Prompt remediation is recommended to mitigate the threat.
OpenCVE Enrichment