CVE-2026-5051EPSS p20.4%

CVE-2026-5051CVE-2026-5051

Description

HashiCorp Vault and Vault Enterprise prior to 2.0.1 audit device validation logic did not consistently apply plugin directory protections when the legacy file audit path option was used. This vulnerability (CVE-2026-5051) is fixed in 2.0.1, 1.21.6, 1.20.11, and 1.19.17.

Scoring

CVSS 4.4 ()
VectorCVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
EPSS0.28% probability of exploitation · percentile 20.4% · 2026-08-15T12:02:44Z
Last modified2026-07-02
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.