CVE-2026-5051
HashiCorp Vault vulnerability analysis and mitigation

Overview

CVE-2026-5051 is a path traversal vulnerability in HashiCorp Vault and Vault Enterprise where the audit device validation logic does not consistently apply plugin directory protections when the legacy file audit path option is used. It affects Vault versions from 1.20.1 up to (but not including) 2.0.1, and Vault Enterprise versions from 1.19.0 up to (but not including) 2.0.1. The vulnerability was disclosed on July 1, 2026, and carries a CVSS v3.1 base score of 4.4 (Medium) (GitHub Advisory, Red Hat Bugzilla).

Technical details

The root cause is classified under CWE-22 (Improper Limitation of a Pathname to a Restricted Directory / Path Traversal) and CWE-807 (Reliance on Untrusted Inputs in a Security Decision). When the legacy file audit device path option is configured, Vault's validation logic fails to consistently enforce plugin directory boundary restrictions, allowing a path traversal condition to occur. Exploitation requires high privileges (administrative access) and high attack complexity over a network vector, meaning an attacker must already hold elevated Vault credentials and craft specific audit device configurations to trigger the bypass (GitHub Advisory, HashiCorp Advisory).

Impact

Successful exploitation allows a high-privileged administrator with network access to Vault to read sensitive audit data outside the intended plugin directory boundaries, resulting in a high confidentiality impact. There is no integrity or availability impact — the vulnerability is limited to unauthorized file/data disclosure. Because exploitation requires existing administrative privileges, the risk of lateral movement is limited, but exposure of audit logs could reveal sensitive operational data about Vault usage, secrets access patterns, and authentication events (GitHub Advisory, HashiCorp Advisory).

Mitigation and workarounds

HashiCorp has released patched versions addressing this vulnerability: 2.0.1, 1.21.6, 1.20.11, and 1.19.17. Organizations should upgrade to one of these versions as the primary remediation. As a workaround, avoid using the legacy file audit path option in audit device configurations, and review existing audit device configurations to ensure plugin directory protections are properly enforced. Restricting administrative access to Vault to only authorized personnel reduces the attack surface given the high-privilege requirement (HashiCorp Advisory, GitHub Advisory).

Community reactions

The vulnerability was assigned by HashiCorp and disclosed via their official security advisory forum (HCSEC-2026-16). Red Hat tracked the issue via Bugzilla with a medium severity rating. No notable independent researcher commentary or significant social media discussion has been observed beyond standard CVE aggregator coverage (Red Hat Bugzilla, HashiCorp Advisory).

Additional resources


SourceThis report was generated using AI

Related HashiCorp Vault vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-39822HIGH7.8
  • Go logoGo
  • cluster-api-provider-vsphere-fips-1.14
NoYesJul 08, 2026
CVE-2026-42306HIGH7.2
  • cAdvisor logocAdvisor
  • cpe:2.3:a:docker:engine
NoYesJun 12, 2026
CVE-2026-41568MEDIUM6.1
  • cAdvisor logocAdvisor
  • beats-9.4
NoYesJun 12, 2026
CVE-2026-42505MEDIUM5.3
  • Go logoGo
  • eks-distro-1.34
NoYesJul 08, 2026
CVE-2026-5051MEDIUM4.4
  • HashiCorp Vault logoHashiCorp Vault
  • splunk-otel-collector
NoYesJul 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management