ID:13050 - Exploit for Improper Authorization in Vault Enterprise and Vault - CVE-2026-5006
Published: September 4, 2026
Vault Enterprise
Vault
Link to public exploit:
Vulnerability description
The vulnerability allows a remote user to access unintended Vault paths.
The vulnerability exists due to improper access control in templated policy paths when rendering identity values containing slash characters. A remote user can manipulate a referenced identity value to access unintended Vault paths.
Exploitation requires control over an identity value referenced by an applicable templated policy.