← back
CVE-2026-5051mediumCWE-22

Audit Log Plugin Directory Guard Bypass via Legacy path Option

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 4.4epss 0.4%
exploitation probability
0.4%top 68% of all CVEs
observed exploitation
nono source reports it
HashiCorp Vault and Vault Enterprise prior to 2.0.1 audit device validation logic did not consistently apply plugin directory protections when the legacy file audit path option was used. This vulnerability (CVE-2026-5051) is fixed in 2.0.1, 1.21.6, 1.20.11, and 1.19.17.
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N