CVE-2026-4525

EUVD-2026-23345
If a Vault auth mount is configured to pass through the "Authorization" header, and the "Authorization" header is used to authenticate to Vault, Vault forwarded the Vault token to the auth plugin backend. Fixed in 2.0.0, 1.21.5, 1.20.10, and 1.19.16.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
HIGH
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 7%
Affected Products (NVD)
VendorProductVersion
hashicorpvault
0.11.2 ≤
𝑥
< 1.19.16
hashicorpvault
0.11.2 ≤
𝑥
< 2.0.0
hashicorpvault
1.20.0 ≤
𝑥
< 1.20.10
hashicorpvault
1.21.0 ≤
𝑥
< 1.21.5
𝑥
= Vulnerable software versions