Missing Authentication for Critical Function in Vault Enterprise and Vault - CVE-2026-5807
Published: April 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper access control in the sys/rekey, sys/generate-root, and sys/rekey-recovery-key endpoints when handling unauthenticated root token generation or rekey requests. A remote attacker can repeatedly initiate or cancel operations to cause a denial of service.
The issue can occupy the single in-progress operation slot and prevent legitimate operators from completing these workflows.
Affected software
Vault
How to mitigate CVE-2026-5807
Vault - update to 2.0.0