🔐 CVE Alert

CVE-2026-5006

MEDIUM 6.8

Vault Vulnerable to Privilege Escalation via Slash Injection in Templated Policy Paths

CVSS Score
6.8
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability was identified in HashiCorp Vault and Vault Enterprise (“Vault”) such that an authenticated attacker may manipulate an identity value referenced by a templated policy path to gain unintended access to Vault paths. An attacker who can control the referenced identity value may include slash ({{/}}) characters that Vault interprets as additional path segments when rendering the policy. This vulnerability, CVE-2026-5006, was fixed in Vault Community Edition 2.0.4 and Vault Enterprise 2.0.4, 1.21.9, 1.20.14, and 1.19.20.

CWE CWE-639
Vendor hashicorp
Product vault
Published Aug 24, 2026
Stay Ahead of the Next One

Get instant alerts for hashicorp vault

Be the first to know when new medium vulnerabilities affecting hashicorp vault are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

HashiCorp / Vault
0.11.0 < 2.0.4
HashiCorp / Vault Enterprise
0.11.0 < 2.0.4

References

NVD ↗ CVE.org ↗ EPSS Data ↗
discuss.hashicorp.com: https://discuss.hashicorp.com/t/hcsec-2026-32-vault-vulnerable-to-privilege-escalation-via-slash-injection-in-templated-policy-paths

Credits

This issue was reported to HashiCorp by Lior Moshe, Uri Rolls, and Daniel Peters, Operating Intelligence ([opint.ai|http://opint.ai/])