Skip to content
HashiCorpCVE-2026-5051

HashiCorp Vault: path traversal

Medium4.4CVE-2026-5051 · Published Jul 1, 2026 · updated Jul 2, 2026

HashiCorp Vault and Vault Enterprise prior to 2.0.1 audit device validation logic did not consistently apply plugin directory protections when the legacy file audit path option was used. This vulnerability (CVE-2026-5051) is fixed in 2.0.1, 1.21.6, 1.20.11, and 1.19.17.

HashiCorp advisory

Affected versions

PackageAffectedFixed in
Vault
Product
>= 1.20.1, < 2.0.12.0.1
Vault Enterprise
Product
>= 1.19.0, < 2.0.12.0.1
Details and references

More HashiCorp advisories

All HashiCorp
Advisory
HashiCorp Nomad: improper authorization
Medium4.2Jul 8
HashiCorp Nomad: link following
High8.7Jul 8
HashiCorp Nomad: missing authorization
High7.7Jul 8
HashiCorp Tooling: link following
Medium4.7Jul 8
HashiCorp Shared library: denial of service
Medium4.9Jul 8
HashiCorp Terraform Enterprise: path traversal
High7.7Jul 6

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.