Sploitus

CVE-2026-12624

No indexed exploits for CVE-2026-12624 yet

Vault’s ACL policy engine did not consistently enforce a wildcard (glob) deny rule against LIST requests made with a trailing slash on the denied path. This may allow a token holding a broader allow rule alongside a narrower wildcard deny rule to enumerate the names of entries beneath a path it was intended to be denied access to. This vulnerability (CVE-2026-12624) is fixed in Vault Community Edition 2.0.3 and Vault Enterprise 2.0.3, 1.21.8, 1.20.13, and 1.19.19.

Fix
Available
CVSS 3.1
4.3 MEDIUM
EPSS
0.2% (10th percentile)
Weakness
CWE-863
NVD status
Received
Published
2026-08-10
Attack patterns
CAPEC-127
CVE-2026-12624 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-12624 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-12624 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.