PT-2026-33406 · Hashicorp+1 · Vault Enterprise+2

·

CVE-2026-5807

·

Published

2026-04-17

·

Updated

2026-06-25

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Vault Community Edition versions prior to 2.0.0 Vault Enterprise versions prior to 2.0.0
Description An unauthenticated attacker can cause a denial-of-service condition by repeatedly initiating or canceling root token generation or rekey operations. This action occupies the single in-progress operation slot, which prevents legitimate operators from completing these specific workflows.
Recommendations Update Vault Community Edition to version 2.0.0. Update Vault Enterprise to version 2.0.0.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-08418
BIT-VAULT-2026-5807
CVE-2026-5807
GHSA-88V5-9HXC-F85R
GO-2026-5247
OPENSUSE-SU-2026:10594-1

Affected Products

Red Os
Vault Community Edition
Vault Enterprise