ID:13050 - Exploit for Improper Authorization in Vault Enterprise and Vault - CVE-2026-5006

 
Main Vulnerability Database Exploits ID:13050 - Exploit for Improper Authorization in Vault Enterprise and Vault - CVE-2026-5006

ID:13050 - Exploit for Improper Authorization in Vault Enterprise and Vault - CVE-2026-5006

Published: September 4, 2026


Vulnerability identifier: #VU145119
Vulnerability risk: Low
CVE-ID: CVE-2026-5006
CWE-ID: CWE-285
Exploitation vector: Remote access
Vulnerable software:
Vault Enterprise
Vault

Link to public exploit:


Vulnerability description

The vulnerability allows a remote user to access unintended Vault paths.

The vulnerability exists due to improper access control in templated policy paths when rendering identity values containing slash characters. A remote user can manipulate a referenced identity value to access unintended Vault paths.

Exploitation requires control over an identity value referenced by an applicable templated policy.


Remediation

Install security update from vendor's website.