CVE-2026-4525Disclosure(hashicorp / vault)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch hashicorp vault systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

If a Vault auth mount is configured to pass through the "Authorization" header, and the "Authorization" header is used to authenticate to Vault, Vault forwarded the Vault token to the auth plugin backend. Fixed in 2.0.0, 1.21.5, 1.20.10, and 1.19.16.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-201

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vault

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-17); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
vault

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-17: 2Mentions · 2026-04-27: 1Patch / Workaround · 2026-04-27: 1Technical Details · 2026-04-17: 2Technical Details · 2026-04-27: 104-1704-27
Signal classification3 categories
Disclosure
133.3%
General
133.3%
Patch
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-172
Disclosure1General1
2026-04-271
Patch1
Full discourse3 posts
  • Giuseppe Paternicola@giuseppe_1337
    Patch

    🚨 HIGH SEVERITY: CVE-2026-4525 (CVSS 7.5) HashiCorp Vault token exposure flaw when Authorization header passthrough is configured. Vault tokens forwarded to auth plugin backends. Fixed: v2.0.0, 1.21.5, 1.20.10, 1.19.16 #CVE #Vulnerability #PatchNow https://t.co/LaBG1L19C6

    Post summary

    The tweet informs users of a high‑severity HashiCorp Vault vulnerability (CVE‑2026‑4525) that exposes tokens via Authorization header passthrough, lists the patched versions, and recommends updating.

    0000047
    27 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4525 If a Vault auth mount is configured to pass through the "Authorization" header, and the "Authorization" header is used to authenticate to Vault, Vault forwarded the Vau… https://www.cve.org/CVERecord?id=CVE-2026-4525

    Post summary

    The post outlines a Vault authentication flaw involving the forwarding of the Authorization header, providing technical details but no PoC, exploit, patch or evidence of active exploitation.

    00000105
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-4525 Vault Token Disclosure via Authorization Header Pass-Through in Auth Mounts https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4525

    Post summary

    The post lists the CVE identifier and gives a brief technical description, but does not mention PoC, exploit, patch, or active exploitation.

    0000051
    4.0K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Apphashicorpvault---
Apphashicorpvault---

Explore more