CVE-2026-4525 Details
Description
If a Vault auth mount is configured to pass through the "Authorization" header, and the "Authorization" header is used to authenticate to Vault, Vault forwarded the Vault token to the auth plugin backend. Fixed in 2.0.0, 1.21.5, 1.20.10, and 1.19.16.
A vulnerability exists in HashiCorp Vault's authentication method header handling. When an auth mount is set to pass through the 'Authorization' header, Vault may inadvertently forward the Vault token to the authentication plugin backend. This issue is present in Vault Community Edition versions 0.11.2 prior to 1.21.4 and Vault Enterprise versions 0.11.2 prior to 1.21.4, 1.20.9, and 1.19.15. The vulnerability arises from improper sanitization of the 'Authorization' header, allowing tokens to be exposed to auth plugins that could misuse them.
Users should upgrade to Vault Community Edition 2.0.0 or Vault Enterprise 2.0.0, 1.21.5, 1.20.10, or 1.19.16. Consult the 'Upgrading Vault' guide for detailed instructions.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 17, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-201 | Insertion of Sensitive Information Into Sent Data | redhat-SADP |
| CWE-201 | Insertion of Sensitive Information Into Sent Data | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| hashicorp vault | >= 0.11.2, < 1.19.16 >= 0.11.2, < 2.0.0 >= 1.20.0, < 1.20.10 >= 1.21.0, < 1.21.5 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 27, 2026 | Initial Analysis | [email protected] |
| Apr 17, 2026 | New CVE Received | [email protected] |