The Vault and Vault Enterprise ("Vault") Google Cloud secrets engine did not preserve existing Google Cloud IAM Conditions upon creating or updating rolesets. Fixed in Vault 1.13.0.
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.