{"id":"BIT-vault-2026-5006","summary":"Vault Vulnerable to Privilege Escalation via Slash Injection in Templated Policy Paths","details":"A vulnerability was identified in HashiCorp Vault and Vault Enterprise (“Vault”) such that an authenticated attacker may manipulate an identity value referenced by a templated policy path to gain unintended access to Vault paths.\n\nAn attacker who can control the referenced identity value may include slash ({{/}}) characters that Vault interprets as additional path segments when rendering the policy.\n\nThis vulnerability, CVE-2026-5006, was fixed in Vault Community Edition 2.0.4 and Vault Enterprise 2.0.4, 1.21.9, 1.20.14, and 1.19.20.","aliases":["CVE-2026-5006"],"modified":"2026-08-28T15:45:36.688179782Z","published":"2026-08-28T14:58:43.560Z","database_specific":{"cpes":["cpe:2.3:a:hashicorp:vault:*:*:*:*:community:go:*:*","cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:go:*:*"],"severity":"Medium"},"references":[{"type":"WEB","url":"https://discuss.hashicorp.com/t/hcsec-2026-32-vault-vulnerable-to-privilege-escalation-via-slash-injection-in-templated-policy-paths"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-5006"}],"affected":[{"package":{"name":"vault","ecosystem":"Bitnami","purl":"pkg:bitnami/vault"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.11.0"},{"fixed":"2.0.4"}]}],"database_specific":{"source":"https://github.com/bitnami/vulndb/tree/main/data/vault/BIT-vault-2026-5006.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N"}]}],"schema_version":"1.9.0"}