CVE-2026-5051: Audit Log Plugin Directory Guard Bypass via Legacy path Option
HashiCorp Vault and Vault Enterprise prior to 2.0.1 audit device validation logic did not consistently apply plugin directory protections when the legacy file audit path option was used.
This vulnerability (CVE-2026-5051) is fixed in 2.0.1, 1.21.6, 1.20.11, and 1.19.17.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.21.6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.20.11 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.19.17
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5051?
The severity of CVE-2026-5051 is medium with a score of 4.4.
How do I fix CVE-2026-5051?
To fix CVE-2026-5051, upgrade to HashiCorp Vault versions 2.0.1, 1.21.6, 1.20.11, or 1.19.17.
What type of vulnerability is CVE-2026-5051?
CVE-2026-5051 is classified as a Path Traversal vulnerability.
What specific problem does CVE-2026-5051 address?
CVE-2026-5051 addresses a bypass in audit device validation logic related to the legacy file audit path option.
Is CVE-2026-5051 applicable to all versions of HashiCorp Vault?
CVE-2026-5051 is applicable to HashiCorp Vault and Vault Enterprise versions prior to 2.0.1.