Synced 18 Jun 2026 05:58 UTC Account
← All products

CVE-2021-41802

LOW severity · CVSS 2.9 · Incorrect permission assignment
2.9CVSS LOW

Summary

HashiCorp Vault and Vault Enterprise through 1.7.4 and 1.8.3 allowed a user with write permission to an entity alias ID sharing a mount accessor with another user to acquire this other user’s policies by merging their identities. Fixed in Vault and Vault Enterprise 1.7.5 and 1.8.4.

Impact & exploitability

Attack vectorAdjacent
Attack complexityLow
Privileges requiredHigh
User interactionRequired
Confidentiality impactLow
Integrity impactNone
Availability impactNone
Exploit probability (EPSS)1%

CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:C/C:L/I:N/A:N

Affected products we track (1)

Recommendation

Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.