CVE-2024-2660
HashiCorp Vault vulnerability analysis and mitigation

Overview

Vault and Vault Enterprise TLS certificates auth method contained a vulnerability (CVE-2024-2660) that failed to correctly validate OCSP responses when one or more OCSP sources were configured. The vulnerability affects Vault and Vault Enterprise versions from 1.14.0 and above, and has been fixed in Vault 1.16.0 and Vault Enterprise 1.16.1, 1.15.7, and 1.14.11. The issue was discovered and disclosed on April 4, 2024 (HashiCorp Discussion).

Technical details

A bug was introduced in the OCSP response handling logic of Vault's TLS certificate authentication method that resulted in signatures and responses from multiple servers not being handled properly. The vulnerability has been assigned a CVSS v3.1 base score of 6.4 (Medium) with the vector string CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H, indicating that it requires adjacent network access and high privileges to exploit (HashiCorp Discussion).

Impact

The vulnerability could allow a malicious actor with privileged network access to successfully authenticate via Vault's TLS certificate authentication method with incorrect certificate status information. This could potentially lead to unauthorized access, disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS) (NetApp Advisory).

Exploitability

The vulnerability requires adjacent network access and high privileges to exploit. While public discussion of this vulnerability exists, no specific exploit details have been publicly disclosed (NetApp Advisory).

Mitigation and workarounds

Customers using the TLS auth method with an OCSP server configured in their Vault installation should evaluate the risk associated with this issue and upgrade to the fixed versions: Vault 1.16.0 or newer, or Vault Enterprise 1.16.1, 1.15.7, 1.14.11, or newer. Users should refer to the Vault upgrading documentation for general guidance and version-specific upgrade notes (HashiCorp Discussion).

Community reactions

The vulnerability was identified by the Vault engineering team internally, demonstrating HashiCorp's proactive approach to security. The issue has been assigned a formal CVE identifier and has been acknowledged by major technology providers such as NetApp, who have begun investigating the potential impact on their products (HashiCorp Discussion).

Additional resources


SourceThis report was generated using AI

Related HashiCorp Vault vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-56865HIGH8.4
  • cAdvisor logocAdvisor
  • dapr-injector-1.16
NoYesAug 13, 2026
CVE-2026-56864HIGH7.5
  • cAdvisor logocAdvisor
  • logto
NoYesAug 13, 2026
CVE-2026-56862HIGH7.5
  • cAdvisor logocAdvisor
  • elastic-otel-collector-9.4
NoYesAug 13, 2026
CVE-2026-56859HIGH7.5
  • cAdvisor logocAdvisor
  • aws-ebs-csi-driver
NoYesAug 13, 2026
CVE-2026-56860MEDIUM5.9
  • cAdvisor logocAdvisor
  • flux-image-automation-controller
NoYesAug 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management