CVE-2026-5006Patch

LOWCVSS 6.8 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was identified in HashiCorp Vault and Vault Enterprise (“Vault”) such that an authenticated attacker may manipulate an identity value referenced by a templated policy path to gain unintended access to Vault paths. An attacker who can control the referenced identity value may include slash ({{/}}) characters that Vault interprets as additional path segments when rendering the policy. This vulnerability, CVE-2026-5006, was fixed in Vault Community Edition 2.0.4 and Vault Enterprise 2.0.4, 1.21.9, 1.20.14, and 1.19.20.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-08-24); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-08-24: 1Mentions · 2026-08-28: 1Patch / Workaround · 2026-08-24: 108-2408-28
Signal classification2 categories
Patch
150.0%
General
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-08-241
Patch1
2026-08-281
General1
Full discourse2 posts
  • Aaliyah@Allys_web3
    General

    Vulnerabilities don’t wait for production. That’s why security layers like HOL Guard are non negotiable for modern infrastructure. ​From handling tricky Vault policy path flaws (CVE-2026-5006) to OpenSSL CMS decrypt overflows and Hive SAML bearer bypasses, keeping automated workflows secure takes constant vigilance. 🛡 ​Protect your stack with our tool: https://hol.org/guard

    Post summary

    The text references several CVEs, including CVE‑2026‑5006, but provides no specific details, PoC, or mitigation instructions, merely encouraging the use of a security tool.

    1305088
    27 followersView on X
  • Kantorcodes | ℏol/acc@Kantorcodes
    Patch

    How to fix, with versions: https://hol.org/blog/cve-2026-5006-vault-slash-injection-templated-policy-paths CVE-2026-5006

    Post summary

    A blog post is linked that provides patch and version information for CVE‑2026‑5006.

    0000047
    11.0K followersView on X

Explore more