Information disclosure in Vault Enterprise and Vault - CVE-2026-4525

 

Information disclosure in Vault Enterprise and Vault - CVE-2026-4525

Published: April 17, 2026


Vulnerability identifier: #VU126409
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-4525
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper header sanitization in the auth plugin backend request processing logic when forwarding the "Authorization" header to an auth plugin backend. A remote user can send a request authenticated with the "Authorization" header to disclose sensitive information.

Exploitation requires an auth mount to be configured to pass through the "Authorization" header.


Affected software

Vault Enterprise
Vault

How to mitigate CVE-2026-4525

Install security update from vendor's website.

Vault Enterprise - addressed in versions 1.19.16, 1.20.10, 1.21.5, 2.0.0
Vault - update to 2.0.0

External References

Related Security Bulletins