CVE-2026-5052 Details
Description
Vault’s PKI engine’s ACME validation did not reject local targets when issuing http-01 and tls-alpn-01 challenges. This may lead to these requests being sent to local network targets, potentially leading to information disclosure. Fixed in Vault Community Edition 2.0.0 and Vault Enterprise 2.0.0, 1.21.5, 1.20.10, and 1.19.16.
A server-side request forgery vulnerability has been identified in HashiCorp Vault's PKI engine, specifically within the ACME validation process. This issue arises because the validation did not properly reject local targets when issuing http-01 and tls-alpn-01 challenges. As a result, requests could be inadvertently sent to local network targets, potentially leading to unauthorized information disclosure. This vulnerability affects Vault Community Edition versions 1.14.0 through 1.21.4, as well as Vault Enterprise versions 1.14.0 through 1.21.4, 1.20.9, and 1.19.15. The vulnerability has been fixed in Vault Community Edition 2.0.0 and Vault Enterprise 2.0.0, 1.21.5, 1.20.10, and 1.19.16.
Users are advised to upgrade to Vault Community Edition 2.0.0 or Vault Enterprise 2.0.0, 1.21.5, 1.20.10, or 1.19.16. For guidance on upgrading Vault, please refer to the official Vault upgrading documentation.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 17, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| hashicorp vault | >= 1.14.0, < 1.19.16 >= 1.14.0, < 2.0.0 >= 1.20.0, < 1.20.10 >= 1.21.0, < 1.21.5 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 27, 2026 | Initial Analysis | [email protected] |
| Apr 17, 2026 | New CVE Received | [email protected] |