CVE-2026-5052Disclosure(hashicorp / vault)

MEDIUMCVSS 8.6 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch hashicorp vault systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Vault’s PKI engine’s ACME validation did not reject local targets when issuing http-01 and tls-alpn-01 challenges. This may lead to these requests being sent to local network targets, potentially leading to information disclosure. Fixed in Vault Community Edition 2.0.0 and Vault Enterprise 2.0.0, 1.21.5, 1.20.10, and 1.19.16.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vault

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-17); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
vault

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-17: 2Mentions · 2026-07-24: 1Active Exploitation · 2026-07-24: 1Patch / Workaround · 2026-07-24: 1Technical Details · 2026-04-17: 204-1707-24
Signal classification2 categories
Disclosure
266.7%
Active Exploitation
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-172
Disclosure2
2026-07-241
Active Exploitation1
Full discourse3 posts
  • Security Arsenal, LLC@SecurityAr58409
    Active Exploitation

    🔒 #CyberSecurity CISA KEV Alert: Check Point and SharePoint Flaws (CVE-2026-16232, CVE-2026-5052… "On July 22, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added two…" 🔗 https://securityarsenal.com/blog/cisa-kev-alert-check-point-and-sharepoint-flaws-cve-2026-16232-cve-2026-50522-detection-and-patching-guide #CyberSecurity #ThreatIntel #cve #zeroday #patchtuesday

    Post summary

    CISA alerts that Check Point and SharePoint vulnerabilities (CVE‑2026‑16232 & CVE‑2026‑5052) are actively exploited and links to a detection and patching guide.

    0000070
    20 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5052 Vault’s PKI engine’s ACME validation did not reject local targets when issuing http-01 and tls-alpn-01 challenges. This may lead to these requests being sent to local n… https://www.cve.org/CVERecord?id=CVE-2026-5052

    Post summary

    This is a disclosure of CVE‑2026‑5052, noting a local target resolution flaw in Vault’s PKI engine during ACME http‑01 and tls‑alpn‑01 challenges, with no PoC, exploit, or patch information provided.

    0000060
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-5052 Information Disclosure via ACME Validation in HashiCorp Vault PKI Engine https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5052

    Post summary

    A new CVE (CVE-2026-5052) for an information disclosure issue in the ACME validation process of HashiCorp Vault PKI Engine has been announced, with a reference link for further details.

    0000048
    4.0K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Apphashicorpvault---
Apphashicorpvault---

Explore more