← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 24, 2026 · 20:32via CVEFeed

CVE-2026-5006 - Vault Vulnerable to Privilege Escalation via Slash Injection in Templated Policy Paths

Brief

CVE ID : CVE-2026-5006

Published : Aug. 24, 2026, 8:32 p. m.

  • 39 minutes ago

Description : A vulnerability was identified in HashiCorp Vault and Vault Enterprise (“Vault”) such that an authenticated attacker may manipulate an identity value referenced by a templated policy path to gain unintended access to Vault paths.

An attacker who can control the referenced identity value may include slash ({{/}}) characters that Vault interprets as additional path segments when rendering the policy.

This vulnerability, CVE-2026-5006, was fixed in Vault Community Edition 2.

  • 4 and Vault Enterprise 2.
  • 4, 1.
  • 9, 1.
  • 14, and 1.
  • 20.

Severity: 6.8

  • MEDIUM
Read more on CVEFeed