PT-2026-33398 · Hashicorp+1 · Vault+1

·

CVE-2026-4525

·

Published

2026-04-16

·

Updated

2026-07-30

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions HashiCorp Vault versions prior to 2.0.0 HashiCorp Vault versions prior to 1.21.5 HashiCorp Vault versions prior to 1.20.10 HashiCorp Vault versions prior to 1.19.16
Description When a Vault auth mount is configured to pass through the 'Authorization' header and that same header is used for authentication to Vault, the system forwards the Vault token to the auth plugin backend, leading to token disclosure.
Recommendations Update to version 2.0.0 Update to version 1.21.5 Update to version 1.20.10 Update to version 1.19.16

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-05665
BIT-VAULT-2026-4525
CVE-2026-4525
GHSA-72GW-FMMR-C4R4
GO-2026-5199
OPENSUSE-SU-2026:21483-1

Affected Products

Red Os
Vault