[WID-SEC-2026-2729] Hashicorp Vault und Vault Enterprise: Mehrere Schwachstellen CVSS Base Score 8.2 (hoch) CVSS Temporal Score 7.1 (hoch) Remoteangriff ja Datum 10.08.2026 Stand 11.08.2026 Mitigation ja Betroffene Systeme Betriebssystem Sonstiges UNIX Produktbeschreibung Vault ist ein identitätsbasiertes System zur Verwaltung von Geheimnissen und Verschlüsselung. Produkte 10.08.2026 Hashicorp Vault <2.0.3 Hashicorp Vault Enterprise <2.0.3 Hashicorp Vault Enterprise <1.21.8 Hashicorp Vault Enterprise <1.20.13 Hashicorp Vault Enterprise <1.19.19 Hashicorp Vault Enterprise <2.0.4 Hashicorp Vault Enterprise <1.21.9 Hashicorp Vault Enterprise <1.20.14 Hashicorp Vault Enterprise <1.19.20 Angriff Angriff Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Hashicorp Vault und Vault Enterpriseausnutzen, um Informationen offenzulegen, Autorisierungsmechanismen zu umgehen und Daten zu manipulieren. CVE Informationen Versionshistorie Feedback zum Advisory geben
Multiple high-severity vulnerabilities (CVSS 8.2) in HashiCorp Vault and Vault Enterprise allow an authenticated remote attacker to disclose information, bypass authorization, and manipulate data. Affected versions include Vault and Vault Enterprise versions prior to 2.0.3, as well as Enterprise versions prior to 1.21.8, 1.20.13, and 1.19.19. A mitigation is available according to the advisory, but specific patched versions or workaround details are not provided in the given text.