CVE-2026-5051
Audit Log Plugin Directory Guard Bypass via Legacy path Option
4.4
MEDIUM
CVSS 3.1
EPSS 0.28%
Description
HashiCorp Vault and Vault Enterprise prior to 2.0.1 audit device validation logic did not consistently apply plugin directory protections when the legacy file audit path option was used. This vulnerability (CVE-2026-5051) is fixed in 2.0.1, 1.21.6, 1.20.11, and 1.19.17.
How to fix CVE-2026-5051
To remediate CVE-2026-5051, upgrade the affected package to a fixed version below.
- —upgrade to 1.19.17 or later
Is CVE-2026-5051 being exploited?
Low — EPSS is 0.3%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- >= 1.19.0, < 1.19.17, >= 1.20.0, < 1.20.11, >= 1.21.0, < 1.21.6, >= 2.0.0, < 2.0.1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.4 | CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N |