PT-2026-33398 · Hashicorp · Vault+1

Published

2026-04-17

·

Updated

2026-04-17

·

CVE-2026-4525

CVSS v3.1

7.5

High

AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
If a Vault auth mount is configured to pass through the "Authorization" header, and the "Authorization" header is used to authenticate to Vault, Vault forwarded the Vault token to the auth plugin backend. Fixed in 2.0.0, 1.21.5, 1.20.10, and 1.19.16.

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-4525

Affected Products

Vault
Vault Enterprise