HashiCorpCVE-2026-5051
HashiCorp Vault: path traversal
Medium4.4CVE-2026-5051 · Published Jul 1, 2026 · updated Jul 2, 2026
HashiCorp Vault and Vault Enterprise prior to 2.0.1 audit device validation logic did not consistently apply plugin directory protections when the legacy file audit path option was used. This vulnerability (CVE-2026-5051) is fixed in 2.0.1, 1.21.6, 1.20.11, and 1.19.17.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Vault Product | >= 1.20.1, < 2.0.1 | 2.0.1 |
| Vault Enterprise Product | >= 1.19.0, < 2.0.1 | 2.0.1 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-22
More HashiCorp advisories
All HashiCorp| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 8 | HashiCorp Nomad: improper authorization | Medium4.2 | 2.0.4+1 more |
| Jul 8 | HashiCorp Nomad: link following | High8.7 | 2.0.4+1 more |
| Jul 8 | HashiCorp Nomad: missing authorization | High7.7 | 2.0.4+1 more |
| Jul 8 | HashiCorp Tooling: link following | Medium4.7 | 0.42.1 |
| Jul 8 | HashiCorp Shared library: denial of service | Medium4.9 | 0.6.0 |
| Jul 6 | HashiCorp Terraform Enterprise: path traversal | High7.7 | 2.0.4 |