CVE-2026-5051 Details
Description
HashiCorp Vault and Vault Enterprise prior to 2.0.1 audit device validation logic did not consistently apply plugin directory protections when the legacy file audit path option was used. This vulnerability (CVE-2026-5051) is fixed in 2.0.1, 1.21.6, 1.20.11, and 1.19.17.
A vulnerability exists in HashiCorp Vault and Vault Enterprise versions prior to 2.0.1, specifically in the audit device validation logic. When the legacy file audit path option was used, the validation did not consistently enforce plugin directory protections. This flaw could allow audit devices to write logs into sensitive plugin paths, bypassing intended safeguards.
Users are advised to upgrade to HashiCorp Vault or Vault Enterprise versions 2.0.1, 1.21.6, 1.20.11, or 1.19.17. For guidance on upgrading Vault, refer to the official HashiCorp Vault upgrade documentation.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 1, 2026CISA-ADP
Assessed Jul 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://discuss.hashicorp.com/t/hcsec-2026-16-vault-audit-device-plugin-directory-guard-bypass-via-legacy-path-option/77536 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| HashiCorp Vault | >= 1.20.1, <= 2.0.0 (semver) |
CPE
Remediation
| |
| HashiCorp Vault Enterprise | >= 1.19.0, <= 2.0.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 1, 2026 | CVE Modified | CISA-ADP |
| Jul 1, 2026 | New CVE Received | [email protected] |
Volerion