CVE-2026-3605 Details
Description
An authenticated user with access to a kvv2 path through a policy containing a glob may be able to delete secrets they were not authorized to read or write, resulting in denial-of-service. This vulnerability did not allow a malicious user to delete secrets across namespaces, nor read any secret data. Fxed in Vault Community Edition 2.0.0 and Vault Enterprise 2.0.0, 1.21.5, 1.20.10, and 1.19.16.
A denial-of-service vulnerability has been identified in HashiCorp Vault's KV V2 secrets engine, affecting both the Community and Enterprise editions. An authenticated user with access to a KV V2 path through a policy containing a glob may be able to delete secrets they were not authorized to read or write. This issue arises from a policy deletion oversight, allowing unauthorized secret deletions, which could disrupt services relying on those secrets. The vulnerability does not permit deletion of secrets across namespaces or access to secret data.
Users are advised to upgrade to Vault Community Edition 2.0.0 or Vault Enterprise versions 2.0.0, 1.21.5, 1.20.10, or 1.19.16.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 17, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-288 | Authentication Bypass Using an Alternate Path or Channel | [email protected] |
| CWE-639 | Authorization Bypass Through User-Controlled Key | redhat-SADP |
Affected Products
| Product | Versions |
|---|---|
| hashicorp vault | >= 0.10.0, < 1.19.16 >= 0.10.0, < 2.0.0 >= 1.20.0, < 1.20.10 >= 1.21.0, < 1.21.5 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 25, 2026 | Initial Analysis | [email protected] |
| Apr 17, 2026 | New CVE Received | [email protected] |