Junglewise Threat Intelligence

CVE-2026-5006: HashiCorp Vault privilege escalation in templated policy paths

CVE-2026-5006 · Severity: medium · CVSS 6.8 · Published 2026-08-24

Technologies: HashiCorp Vault, HashiCorp Vault Enterprise. Vendors: HashiCorp.

Executive brief

HashiCorp Vault is a secrets management system that uses policies to control what data different users and applications can access. An authenticated attacker can inject slash characters into identity values that are referenced in policy templates, causing Vault to interpret these as additional path segments and grant unintended access to secrets. This allows a compromised or malicious user to read sensitive data they should not have permission to access.

Technical details

The vulnerability is a path traversal/injection flaw in Vault's templated policy path rendering mechanism. When policies reference identity values (such as entity metadata) using template syntax like {{identity.entity.metadata.department}}, an attacker who controls that identity value can insert forward slash (/) characters. Vault interprets these slashes as path separators during policy rendering, causing the expanded path to include unintended segments that grant access to secrets outside the policy author's intent. The attack requires authentication and the ability to modify an identity value referenced by a templated policy. The fix was released in Vault Community Edition 2.0.4 and Vault Enterprise versions 2.0.4, 1.21.9, 1.20.14, and 1.19.20, with an optional configuration flag (deny_slash_in_templated_paths) to prevent slash characters in rendered identity template values.

Affected products

  • HashiCorp Vault 0.11.0 to 2.0.3
  • HashiCorp Vault Enterprise 0.11.0 to 2.0.3, 1.21.0 to 1.21.8, 1.20.0 to 1.20.13, 1.19.0 to 1.19.19

Timeline

  • 2026-08-24: disclosed: CVE-2026-5006 / HCSEC-2026-32 published
  • 2026-08-24: patched: Vault Community Edition 2.0.4 and Vault Enterprise 2.0.4, 1.21.9, 1.20.14, 1.19.20 released

References

Related threats