Auth Bypass via Identity Path Manipulation in HashiCorp Vault 2.0.4
CVE-2026-5006 Published on August 24, 2026
Vault Vulnerable to Privilege Escalation via Slash Injection in Templated Policy Paths
A vulnerability was identified in HashiCorp Vault and Vault Enterprise (Vault) such that an authenticated attacker may manipulate an identity value referenced by a templated policy path to gain unintended access to Vault paths.
An attacker who can control the referenced identity value may include slash ({{/}}) characters that Vault interprets as additional path segments when rendering the policy.
This vulnerability, CVE-2026-5006, was fixed in Vault Community Edition 2.0.4 and Vault Enterprise 2.0.4, 1.21.9, 1.20.14, and 1.19.20.
Weakness Type
What is an Insecure Direct Object Reference / IDOR Vulnerability?
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
CVE-2026-5006 has been classified to as an Insecure Direct Object Reference / IDOR vulnerability or weakness.
Products Associated with CVE-2026-5006
Want to know whenever a new CVE is published for HashiCorp Vault? stack.watch will email you.
Affected Versions
HashiCorp Vault:- Version 0.11.0 and below 2.0.4 is affected.
- Version 0.11.0 and below 2.0.4 is affected.