Auth Bypass via Identity Path Manipulation in HashiCorp Vault 2.0.4
CVE-2026-5006 Published on August 24, 2026

Vault Vulnerable to Privilege Escalation via Slash Injection in Templated Policy Paths
A vulnerability was identified in HashiCorp Vault and Vault Enterprise (Vault) such that an authenticated attacker may manipulate an identity value referenced by a templated policy path to gain unintended access to Vault paths. An attacker who can control the referenced identity value may include slash ({{/}}) characters that Vault interprets as additional path segments when rendering the policy. This vulnerability, CVE-2026-5006, was fixed in Vault Community Edition 2.0.4 and Vault Enterprise 2.0.4, 1.21.9, 1.20.14, and 1.19.20.

NVD

Weakness Type

What is an Insecure Direct Object Reference / IDOR Vulnerability?

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

CVE-2026-5006 has been classified to as an Insecure Direct Object Reference / IDOR vulnerability or weakness.


Products Associated with CVE-2026-5006

Want to know whenever a new CVE is published for HashiCorp Vault? stack.watch will email you.

 

Affected Versions

HashiCorp Vault: HashiCorp Vault Enterprise: