What is CVE-2026-12624?
CVE-2026-12624 is a vulnerability in Vault's ACL policy engine. A wildcard (glob) deny rule was not consistently enforced against LIST requests with a trailing slash on the denied path. This could allow a token with a broader allow rule to enumerate entry names beneath a restricted path; Vault administrators should review their ACL policies.
Azərbaycanca: CVE-2026-12624, Vault-un ACL siyasət mühərrikində aşkarlanıb. Müəyyən wildcard (glob) inkar qaydaları, xüsusilə LIST sorğularında, yolun sonunda slash (/) işarəsi olduqda ardıcıl tətbiq edilmir. Bu, daha geniş icazəyə malik tokenin məhdudlaşdırılmış yolu sadalamasına imkan verə bilər; Vault administratorları ACL qaydalarını yoxlamalıdır.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
Which component of Vault is affected by CVE-2026-12624?
CVE-2026-12624 affects Vault's ACL policy engine.
What can be achieved by exploiting this vulnerability?
A token with a broader allow rule can enumerate entry names beneath a restricted path.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.