Privilege Escalation Vulnerability in HashiCorp Vault and Vault Enterprise
CVE-2026-5006
6.8MEDIUM
What is CVE-2026-5006?
A flaw in HashiCorp Vault and Vault Enterprise allows an authenticated attacker to manipulate identity values in templated policy paths. By controlling these identity values, attackers can exploit slash ({{/}}) characters, leading to unauthorized access to sensitive Vault paths. This misinterpretation by the Vault system may result in privilege escalation, emphasizing the need for immediate updates to secure the affected versions.
Affected Version(s)
Vault 64 bit 0.11.0 < 2.0.4
Vault Enterprise 64 bit 0.11.0 < 2.0.4
References
CVSS V3.1
Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This issue was reported to HashiCorp by Lior Moshe, Uri Rolls, and Daniel Peters, Operating Intelligence ([opint.ai|http://opint.ai/])