PT-2026-33406 · Hashicorp · Vault Enterprise+1

Atuin Automated Vulnerability Discovery Engine

+1

·

Published

2026-04-17

·

Updated

2026-04-27

·

CVE-2026-5807

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Vault Community Edition versions prior to 2.0.0 Vault Enterprise versions prior to 2.0.0
Description An unauthenticated attacker can cause a denial-of-service condition by repeatedly initiating or canceling root token generation or rekey operations. This action occupies the single in-progress operation slot, which prevents legitimate operators from completing these specific workflows.
Recommendations Update Vault Community Edition to version 2.0.0. Update Vault Enterprise to version 2.0.0.

Fix

DoS

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

BIT-VAULT-2026-5807
CVE-2026-5807
GHSA-88V5-9HXC-F85R
OPENSUSE-SU-2026:10594-1

Affected Products

Vault Community Edition
Vault Enterprise