CVE-2022-36129: Hashicorp Vault

Critical severity, CVSS 9.1. EPSS: 1.6% chance of exploitation in the next 30 days.

HashiCorp Vault Enterprise 1.7.0 through 1.9.7, 1.10.4, and 1.11.0 clusters using Integrated Storage expose an unauthenticated API endpoint that could be abused to override the voter status of a node within a Vault HA cluster, introducing potential for future data loss or catastrophic failure. Fixed in Vault Enterprise 1.9.8, 1.10.5, and 1.11.1.

Affected products

  • Hashicorp Vault: from 1.7.0, up to and including 1.9.7; from 1.10.0, up to and including 1.10.4; version 1.11.0 only

Published 2022-07-26. Last modified 2026-06-17.