
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5006 is a privilege escalation vulnerability in HashiCorp Vault and Vault Enterprise that allows an authenticated attacker to bypass intended access controls by injecting slash characters into identity values referenced by templated policy paths. Disclosed on August 24, 2026, it affects Vault Community Edition and Vault Enterprise from version 0.11.0 up to (but not including) the patched releases. The vulnerability carries a CVSS v3.1 base score of 6.8 (Medium/High) (GitHub Advisory).
The root cause is classified as CWE-639 (Authorization Bypass Through User-Controlled Key): Vault's policy engine renders templated policy paths by substituting identity values (e.g., entity names, aliases) without sanitizing slash (/) characters. When an attacker controls an identity value and embeds slash characters, Vault interprets them as additional path segments during policy rendering, effectively allowing the attacker to traverse into path namespaces they are not authorized to access. Exploitation requires the attacker to have low-level authenticated access and the ability to influence the identity value referenced in a templated policy (e.g., by controlling their own entity name or alias). No public proof-of-concept code has been identified (GitHub Advisory, HashiCorp Advisory).
A successful exploit allows a low-privileged authenticated user to read or modify Vault secrets and data at paths they are not authorized to access, resulting in high confidentiality and integrity impact with no availability impact. Depending on the secrets stored in the unauthorized paths (e.g., credentials, certificates, encryption keys), exploitation could enable lateral movement within an organization's infrastructure or exposure of highly sensitive data. The scope is limited to the affected Vault instance, but the breadth of impact depends on what secrets are accessible via the bypassed policy paths (GitHub Advisory).
There is no evidence of public proof-of-concept code or active in-the-wild exploitation as of the disclosure date. The EPSS score is 0.0, indicating a very low current probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires authentication and the ability to control an identity value referenced in a templated policy, which raises the attack complexity (GitHub Advisory).
secret/data/{{identity.entity.name}}/*) that reference a value the attacker can control.legitimate/../../admin or a similar path traversal string./) characters, which is atypical for standard identity naming conventions.vault list identity/entity/name and inspect for anomalous values.HashiCorp has released patches addressing this vulnerability. Users should upgrade to Vault Community Edition 2.0.4 or Vault Enterprise 2.0.4, 1.21.9, 1.20.14, or 1.19.20 as soon as possible. As interim mitigations, administrators should review templated policy configurations to ensure identity values used in path templates are validated or restricted, and implement additional access controls limiting which users can modify their own identity values (entity names, aliases, metadata). Auditing Vault identity stores for entity names or aliases containing slash characters is also recommended (GitHub Advisory, HashiCorp Advisory).
HashiCorp disclosed the vulnerability through their official security advisory forum (HCSEC-2026-32) on August 24, 2026, providing patched versions and remediation guidance. No notable independent researcher commentary or significant social media discussion has been identified beyond standard vulnerability aggregator coverage at the time of disclosure (HashiCorp Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."