CVE-2026-5006
MEDIUM 6.8EPSS 0.2%
A vulnerability was identified in HashiCorp Vault and Vault Enterprise (“Vault”) such that an authenticated attacker may manipulate an identity value referenced by a templated policy path to gain unintended access to Vault paths. An attacker who can control the referenced identity value may include slash ({{/}}) characters that Vault interprets as additional path segments when rendering the policy. This vulnerability, CVE-2026-5006, was fixed in Vault Community Edition 2.0.4 and Vault Enterprise 2.0.4, 1.21.9, 1.20.14, and 1.19.20.
- CVSS v3.1
- 6.8 MEDIUM
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N - EPSS
- 0.17% chance of exploitation in the next 30 days, 7th percentile
- Published
- 2026-08-24
- Updated
- 2026-08-26
Proof-of-concept exploits (1)
- M4xSec/My-Exploits1★ · 2026-08-31