← Back to feed Search feed

HashiCorp Vault vulnerabilities

12 entries matching vault — updated 2026-09-18 · vulnfeed

CVE / IDTitleSeverityCVSSEPSSSourceDate
CVE-2026-54053Many Notes is a Markdown note-taking web application designed for simplicity. Prior to 0.16.0, the ZIP vault import implCRITICAL9.652%ileNVD2026-09-17
CVE-2026-54618Obsidian Web MCP is a secure remote MCP server for Obsidian vaults. Prior to 0.2.0, /oauth/authorize issues an authorizaCRITICAL9.434%ileNVD2026-09-17
CVE-2026-54597ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to versiHIGH8.324%ileNVD2026-09-17
CVE-2026-86465Apache Airflow Akeyless provider: the Akeyless secrets backend's team-scope guard can be bypassed with a user-controlledMEDIUM6.555%ileNVD2026-09-16
CVE-2026-57441MCPVault is a lightweight Model Context Protocol server for safe access to files in an Obsidian vault. Prior to 0.11.4, HIGH8.47%ileNVD2026-09-15
CVE-2026-57442MCPVault is a lightweight Model Context Protocol server for safe access to files in an Obsidian vault. Prior to 0.11.5, MEDIUM6.96%ileNVD2026-09-15
CVE-2026-55775OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, OpenBao users granted capabilities oLOW2.330%ileNVD2026-09-15
CVE-2026-55774OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, an OpenBao user with access to sys/lLOW2.138%ileNVD2026-09-15
CVE-2026-90969Improper access control in the vault entry listing feature in Devolutions Server 2026.2.16 and earlier allows an authentUNKNOWN4%ileNVD2026-09-15
CVE-2026-77884Gallery - Private Photo Vault 1.0.41 starts an unauthenticated HTTP server that is reachable from the local network. TheHIGH7.125%ileNVD2026-09-14
CVE-2026-55102hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.2, every API method in srcMEDIUM5.82%ileNVD2026-09-14
CVE-2026-62825Azure Key Vault Elevation of Privilege VulnerabilityCRITICAL10.052%ileMicrosoft2026-07-14