CVE-2026-5807: Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations
Vault is vulnerable to a denial-of-service condition where an unauthenticated attacker can repeatedly initiate or cancel root token generation or rekey operations, occupying the single in-progress operation slot. This prevents legitimate operators from completing these workflows. This vulnerability, CVE-2026-5807, is fixed in Vault Community Edition 2.0.0 and Vault Enterprise 2.0.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5807?
CVE-2026-5807 is classified as a denial-of-service vulnerability that could significantly disrupt service availability.
How do I fix CVE-2026-5807?
To mitigate CVE-2026-5807, upgrade to Vault versions 2.0.0 or later, where the vulnerability has been addressed.
What is the potential impact of CVE-2026-5807?
CVE-2026-5807 allows an unauthenticated attacker to cause a denial-of-service condition by repeatedly initiating or canceling root token operations.
Which versions of Vault are affected by CVE-2026-5807?
CVE-2026-5807 affects all versions of HashiCorp Vault Community Edition and Enterprise up to, but not including, version 2.0.0.
Who should be concerned about CVE-2026-5807?
Administrators of HashiCorp Vault versions prior to 2.0.0 should be particularly concerned about CVE-2026-5807 due to its denial-of-service capabilities.