PT-2026-33406 · Hashicorp · Vault Enterprise+1
Atuin Automated Vulnerability Discovery Engine
+1
·
Published
2026-04-17
·
Updated
2026-04-27
·
CVE-2026-5807
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Vault Community Edition versions prior to 2.0.0
Vault Enterprise versions prior to 2.0.0
Description
An unauthenticated attacker can cause a denial-of-service condition by repeatedly initiating or canceling root token generation or rekey operations. This action occupies the single in-progress operation slot, which prevents legitimate operators from completing these specific workflows.
Recommendations
Update Vault Community Edition to version 2.0.0.
Update Vault Enterprise to version 2.0.0.
Fix
DoS
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vault Community Edition
Vault Enterprise