{"record":"HashiCorp Vault evidence record","url":"https://nexalign.io/vendors/hashicorp-vault","vendor":{"slug":"hashicorp-vault","name":"HashiCorp Vault","domain":"hashicorp.com","category":"pam","categoryLabel":"Privileged access management"},"lastChecked":"2026-07-17T16:17:38.583Z","coverage":{"earliest":"2018-12-05T09:00:00.000Z","latest":"2026-07-06T08:24:10.000Z"},"terms":{"isRanking":false,"isRating":false,"statesSuitability":false,"note":"This is a record of what public sources hold about a named company. It states no ranking, no rating and no suitability verdict, and none may be derived from it. An absent or small record means the public registers publish little under that name; it is not evidence that a product is secure. A larger advisory count generally reflects wider deployment and more scrutiny rather than a weaker product.","licence":"https://nexalign.io/vendors#licence","corrections":"info@nexalign.io"},"totals":{"evidenceItems":70,"kindsOfSource":4,"attributedAdvisories":26,"knownExploited":0,"registerEntriesNotAttributable":28,"practitionerThreads":7,"independentItems":1,"vendorPublishedItems":0,"shareFromSourcesTheVendorDoesNotControl":1},"sources":[{"source":"European Vulnerability Database","operator":"ENISA, European Union","classification":"authoritative","items":28,"latest":"2026-07-06T08:24:10.000Z"},{"source":"CERT-Bund security advisories","operator":"BSI, Federal Republic of Germany","classification":"authoritative","items":26,"latest":"2026-07-02T11:05:51.420Z"},{"source":"Engineering discussions","operator":"Hacker News, public threads","classification":"independent","items":13,"latest":"2026-06-21T10:57:31.000Z"},{"source":"Analyst, review and reference sources","operator":"Recognised analysts, review marketplaces and technology press","classification":"independent","items":3,"latest":"2026-07-03T04:22:45.811Z"}],"advisories":{"shown":6,"total":26,"truncated":true,"fullList":"https://nexalign.io/vendors/hashicorp-vault/advisories","items":[{"id":"WID-SEC-2026-2167","description":"Affected products: Hashicorp Vault","severity":"low","cvss":4.4,"knownExploited":false,"date":"2026-07-02T11:05:51.420Z","sources":["https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2167"]},{"id":"WID-SEC-2026-1164","description":"Affected products: Hashicorp Vault","severity":"high","cvss":8.1,"knownExploited":false,"date":"2026-04-17T09:44:11.836Z","sources":["https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1164"]},{"id":"WID-SEC-2025-2396","description":"Affected products: Red Hat Enterprise Linux, Hashicorp Vault","severity":"high","cvss":8.1,"knownExploited":false,"date":"2025-11-25T11:12:16.074Z","sources":["https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-2396"]},{"id":"WID-SEC-2025-1925","description":"Affected products: Hashicorp Vault","severity":"medium","cvss":7.5,"knownExploited":false,"date":"2025-10-24T08:34:43.940Z","sources":["https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-1925"]},{"id":"WID-SEC-2025-1730","description":"Affected products: Hashicorp Vault","severity":"medium","cvss":5.9,"knownExploited":false,"date":"2025-08-08T08:29:46.220Z","sources":["https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-1730"]},{"id":"WID-SEC-2025-1734","description":"Affected products: Hashicorp Vault","severity":"medium","cvss":5.3,"knownExploited":false,"date":"2025-08-07T09:39:19.262Z","sources":["https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-1734"]}]},"practitionerThreads":{"shown":5,"total":7,"truncated":true,"items":[{"title":"Enterprise for OpenBAO – Open Source HashiCorp Vault alternative","context":"Hacker News","url":"https://news.ycombinator.com/item?id=47407529","date":"2026-03-17T01:35:01.000Z"},{"title":"HashiCorp Vault is overhyped, and Mozilla SOPS with KMS and Git is underrated (2019)","context":"Hacker News","url":"https://news.ycombinator.com/item?id=46844857","date":"2026-02-01T09:42:02.000Z"},{"title":"HashiCorp Vault is overhyped, and Mozilla SOPS with KMS and Git is underrated","context":"Hacker News","url":"https://news.ycombinator.com/item?id=45991997","date":"2025-11-20T12:42:02.000Z"},{"title":"Zero-day flaws in authentication, identity, authorization in HashiCorp Vault","context":"Hacker News","url":"https://news.ycombinator.com/item?id=44821434","date":"2025-08-07T07:01:42.000Z"},{"title":"Researchers Uncover RCE Attack Chains in HashiCorp Vault and CyberArk Conjur","context":"Hacker News","url":"https://news.ycombinator.com/item?id=44821250","date":"2025-08-07T06:25:35.000Z"}]},"independentCoverage":{"shown":1,"total":1,"truncated":false,"items":[{"title":"HashiCorp Vault Reviews, Competitors and Pricing","host":"peerspot.com","url":"https://www.peerspot.com/products/hashicorp-vault-reviews","date":null}]},"vendorPublished":{"shown":0,"total":0,"truncated":false,"items":[]},"openQuestions":["A further 28 register entries mention HashiCorp Vault without naming a product of HashiCorp Vault as affected. They are excluded rather than counted as vulnerabilities.","Pricing, contract terms, notice periods and support commitments are not part of any public register. They come from the vendor and belong in a negotiation record.","Certification status such as ISO 27001, SOC 2 or BSI C5 has to be checked against the current certificate and its stated scope. A valid certificate can still exclude the product being bought."]}