5.3
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Description
Vault’s PKI engine’s ACME validation did not reject local targets when issuing http-01 and tls-alpn-01 challenges. This may lead to these requests being sent to local network targets, potentially leading to information disclosure. Fixed in Vault Community Edition 2.0.0 and Vault Enterprise 2.0.0, 1.21.5, 1.20.10, and 1.19.16.
Basic Information
ID
CVE-2026-5052
Source
HashiCorp
Published
Apr 17, 2026 at 02:55
Affected Product
Vendor
HashiCorp
Product
Vault
Version
1.15.0
Affected Versions
HashiCorp Vault 1.15.0
HashiCorp Vault Enterprise 1.15.0
HashiCorp Vault Enterprise 1.15.0