Hashicorp · Vault · CVE-2026-5051
**Name of the Vulnerable Software and Affected Versions**
HashiCorp Vault versions prior to 2.0.1
HashiCorp Vault Enterprise versions prior to 2.0.1
**Description**
Audit device validation logic fails to consistently apply plugin directory protections when the legacy file audit path option is utilized.
**Recommendations**
Update HashiCorp Vault to version 2.0.1, 1.21.6, 1.20.11, or 1.19.17.
Update HashiCorp Vault Enterprise to version 2.0.1, 1.21.6, 1.20.11, or 1.19.17.