Impact
Vault and Vault Enterprise failed to consistently evaluate ACL policies against the canonical form of resource and policy names. An authenticated user who has been granted delegated permissions can circumvent an explicit deny restriction, gaining access to protected resources or assigning policies that should be blocked. This flaw can lead to privilege escalation within the Vault environment.
Affected Systems
HashiCorp Vault Community Edition older than 2.1.2, and Vault Enterprise older than 2.1.2, 1.21.12, 1.20.17, or 1.19.23 are affected. Newer releases have been fixed, although all earlier releases may still be vulnerable.
Risk and Exploitability
The CVSS score is 7.2, indicating a high severity. The EPSS score is not available, but the vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires an authenticated user with delegated permissions to craft or modify ACLs that exploit the evaluation inconsistency. Successful exploitation yields elevated privileges and can compromise sensitive Vault secrets or data.
OpenCVE Enrichment