CVE-2026-5006: Vault Vulnerable to Privilege Escalation via Slash Injection in Templated Policy Paths
A vulnerability was identified in HashiCorp Vault and Vault Enterprise (“Vault”) such that an authenticated attacker may manipulate an identity value referenced by a templated policy path to gain unintended access to Vault paths.
An attacker who can control the referenced identity value may include slash ({{/}}) characters that Vault interprets as additional path segments when rendering the policy.
This vulnerability, CVE-2026-5006, was fixed in Vault Community Edition 2.0.4 and Vault Enterprise 2.0.4, 1.21.9, 1.20.14, and 1.19.20.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
HashiCorp Vault Community Editionto a version that resolves this vulnerability.Fixed in 2.0.4Patch CVE-2026-5006 - Upgrade
Upgrade
HashiCorp Vault Enterpriseto a version that resolves this vulnerability.Fixed in 2.0.4Patch CVE-2026-5006 - Upgrade
Upgrade
HashiCorp Vault Enterpriseto a version that resolves this vulnerability.Fixed in 1.21.9Patch CVE-2026-5006 - Upgrade
Upgrade
HashiCorp Vault Enterpriseto a version that resolves this vulnerability.Fixed in 1.20.14Patch CVE-2026-5006 - Upgrade
Upgrade
HashiCorp Vault Enterpriseto a version that resolves this vulnerability.Fixed in 1.19.20Patch CVE-2026-5006
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Vault deployments are exposed if they use templated policy paths that reference an identity value an authenticated attacker can control. The attacker must be able to place slash characters in that referenced value.
What access does an attacker need to exploit it?
The attacker must already be authenticated and have the ability to control an identity value used in a templated policy path. Exploitation does not require user interaction, but the documented attack complexity is high.
Which versions contain the fix?
The issue is fixed in Vault Community Edition 2.0.4 and Vault Enterprise 2.0.4, 1.21.9, 1.20.14, and 1.19.20.