Vulnerability Description
Vault’s PKI engine’s ACME validation did not reject local targets when issuing http-01 and tls-alpn-01 challenges. This may lead to these requests being sent to local network targets, potentially leading to information disclosure. Fixed in Vault Community Edition 2.0.0 and Vault Enterprise 2.0.0, 1.21.5, 1.20.10, and 1.19.16.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hashicorp | Vault | >= 1.14.0, < 1.19.16 |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-5052?
CVE-2026-5052 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Vault’s PKI engine’s ACME validation did not reject local targets when issuing http-01 and tls-alpn-01 challenges. This may lead to these requests being sent to local network targets, potentially lead...
How severe is CVE-2026-5052?
CVE-2026-5052 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-5052?
Check the references section above for vendor advisories and patch information. Affected products include: Hashicorp Vault.