CVE-2026-3605 — An authenticated user with access to a kvv2 path through a policy containing a glob may be able to delete secrets they were not authorized to read or write, resulting in denial-of-service. This vulner — CVE Database · The Intelligence Room