SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-5006

MEDIUM · CVSS 6.8 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-08-24 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

HashiCorp Vault and Vault Enterprise are vulnerable to a manipulation attack where an authenticated user can exploit templated policy paths by injecting slash characters into identity values, potentially gaining unauthorized access to sensitive Vault paths. Organizations using these versions of Vault should prioritize patching to mitigate the risk of privilege escalation and unauthorized data access. The vulnerability has been addressed in Vault Community Edition 2.0.4 and specific versions of Vault Enterprise.

CVE
CVE-2026-5006
Severity
MEDIUM
CVSS
6.8
EPSS
0.17%

Original NVD Description

A vulnerability was identified in HashiCorp Vault and Vault Enterprise (“Vault”) such that an authenticated attacker may manipulate an identity value referenced by a templated policy path to gain unintended access to Vault paths. An attacker who can control the referenced identity value may include slash ({{/}}) characters that Vault interprets as additional path segments when rendering the policy. This vulnerability, CVE-2026-5006, was fixed in Vault Community Edition 2.0.4 and Vault Enterprise 2.0.4, 1.21.9, 1.20.14, and 1.19.20.