{"api_version":"1","generated_at":"2026-07-05T00:46:38+00:00","cve":"CVE-2026-5051","urls":{"html":"https://cve.report/CVE-2026-5051","api":"https://cve.report/api/cve/CVE-2026-5051.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-5051","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-5051"},"summary":{"title":"Audit Log Plugin Directory Guard Bypass via Legacy path Option","description":"HashiCorp Vault and Vault Enterprise prior to 2.0.1 audit device validation logic did not consistently apply plugin directory protections when the legacy file audit path option was used. \n\nThis vulnerability (CVE-2026-5051) is fixed in 2.0.1, 1.21.6, 1.20.11, and 1.19.17.","state":"PUBLISHED","assigner":"HashiCorp","published_at":"2026-07-01 18:16:36","updated_at":"2026-07-02 17:54:27"},"problem_types":["CWE-22","CWE-22 CWE-22: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)"],"metrics":[{"version":"3.1","source":"security@hashicorp.com","type":"Secondary","score":"4.4","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N","baseScore":4.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"4.4","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N","data":{"baseScore":4.4,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N","version":"3.1"}}],"references":[{"url":"https://discuss.hashicorp.com/t/hcsec-2026-16-vault-audit-device-plugin-directory-guard-bypass-via-legacy-path-option/77536","name":"https://discuss.hashicorp.com/t/hcsec-2026-16-vault-audit-device-plugin-directory-guard-bypass-via-legacy-path-option/77536","refsource":"security@hashicorp.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-5051","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-5051","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"HashiCorp","product":"Vault","version":"affected 1.20.1 2.0.1 semver","platforms":["64 bit","32 bit","x86","ARM","MacOS","Windows","Linux"]},{"source":"CNA","vendor":"HashiCorp","product":"Vault Enterprise","version":"affected 1.19.0 2.0.1 semver","platforms":["64 bit","32 bit","x86","ARM","MacOS","Windows","Linux"]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"This issue was identified and reported by Vipin Chaudhary.","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"5051","cve":"CVE-2026-5051","epss":"0.002780000","percentile":"0.196670000","score_date":"2026-07-04","updated_at":"2026-07-05 00:02:26"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-5051","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-07-01T17:54:21.733151Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-07-01T17:54:43.314Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","platforms":["64 bit","32 bit","x86","ARM","MacOS","Windows","Linux"],"product":"Vault","repo":"https://github.com/hashicorp/vault","vendor":"HashiCorp","versions":[{"changes":[{"at":"1.20.11","status":"unaffected"},{"at":"1.21.6","status":"unaffected"},{"at":"2.0.1","status":"unaffected"}],"lessThan":"2.0.1","status":"affected","version":"1.20.1","versionType":"semver"}]},{"defaultStatus":"unaffected","platforms":["64 bit","32 bit","x86","ARM","MacOS","Windows","Linux"],"product":"Vault Enterprise","repo":"https://github.com/hashicorp/vault","vendor":"HashiCorp","versions":[{"changes":[{"at":"1.19.17","status":"unaffected"},{"at":"1.20.11","status":"unaffected"},{"at":"1.21.6","status":"unaffected"},{"at":"2.0.1","status":"unaffected"}],"lessThan":"2.0.1","status":"affected","version":"1.19.0","versionType":"semver"}]}],"credits":[{"lang":"en","value":"This issue was identified and reported by Vipin Chaudhary."}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>HashiCorp Vault and Vault Enterprise prior to 2.0.1 audit device validation logic did not consistently apply plugin directory protections when the legacy file audit path option was used. \n\nThis vulnerability (CVE-2026-5051) is fixed in 2.0.1, 1.21.6, 1.20.11, and 1.19.17.</p><br/>"}],"value":"HashiCorp Vault and Vault Enterprise prior to 2.0.1 audit device validation logic did not consistently apply plugin directory protections when the legacy file audit path option was used. \n\nThis vulnerability (CVE-2026-5051) is fixed in 2.0.1, 1.21.6, 1.20.11, and 1.19.17."}],"impacts":[{"capecId":"CAPEC-126","descriptions":[{"lang":"en","value":"CAPEC-126: Path Traversal"}]}],"metrics":[{"cvssV3_1":{"baseScore":4.4,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-22","description":"CWE-22: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-07-01T17:10:56.918Z","orgId":"67fedba0-ff2e-4543-ba5b-aa93e87718cc","shortName":"HashiCorp"},"references":[{"url":"https://discuss.hashicorp.com/t/hcsec-2026-16-vault-audit-device-plugin-directory-guard-bypass-via-legacy-path-option/77536"}],"source":{"advisory":"HCSEC-2026-16","discovery":"EXTERNAL"},"title":"Audit Log Plugin Directory Guard Bypass via Legacy path Option"}},"cveMetadata":{"assignerOrgId":"67fedba0-ff2e-4543-ba5b-aa93e87718cc","assignerShortName":"HashiCorp","cveId":"CVE-2026-5051","datePublished":"2026-07-01T17:10:56.918Z","dateReserved":"2026-03-27T17:45:14.081Z","dateUpdated":"2026-07-01T17:54:43.314Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-07-01 18:16:36","lastModifiedDate":"2026-07-02 17:54:27","problem_types":["CWE-22","CWE-22 CWE-22: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)"],"metrics":{"cvssMetricV31":[{"source":"security@hashicorp.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N","baseScore":4.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":0.7,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-01T17:54:21.733151Z","id":"CVE-2026-5051","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"5051","Ordinal":"1","Title":"Audit Log Plugin Directory Guard Bypass via Legacy path Option","CVE":"CVE-2026-5051","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"5051","Ordinal":"1","NoteData":"HashiCorp Vault and Vault Enterprise prior to 2.0.1 audit device validation logic did not consistently apply plugin directory protections when the legacy file audit path option was used. \n\nThis vulnerability (CVE-2026-5051) is fixed in 2.0.1, 1.21.6, 1.20.11, and 1.19.17.","Type":"Description","Title":"Audit Log Plugin Directory Guard Bypass via Legacy path Option"}]}}}