<Vulnerability name="CVE-2026-5051">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Moderate</ThreatSeverity>
    <PublicDate>2026-07-01T17:10:56</PublicDate>
    <Bugzilla id="2496100" url="https://bugzilla.redhat.com/show_bug.cgi?id=2496100" xml:lang="en:us">
Vault: Vault Enterprise: HashiCorp Vault: Audit device validation bypass via legacy file audit path option
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>4.4</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-807</CWE>
    <Details xml:lang="en:us" source="Mitre">
HashiCorp Vault and Vault Enterprise prior to 2.0.1 audit device validation logic did not consistently apply plugin directory protections when the legacy file audit path option was used. 

This vulnerability (CVE-2026-5051) is fixed in 2.0.1, 1.21.6, 1.20.11, and 1.19.17.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in HashiCorp Vault and Vault Enterprise. The audit device validation logic did not consistently apply plugin directory protections when a legacy file audit path option was used. This inconsistency could allow an attacker to bypass security controls, potentially leading to unauthorized access to sensitive information.
    </Details>
    <Statement xml:lang="en:us">
A flaw was found in HashiCorp Vault's server-side audit device validation logic. Red Hat products that bundle the Vault Go client library (github.com/hashicorp/vault/api) are not affected because they only use the client SDK to connect to external Vault servers for secrets/KMS operations. The vulnerable code is in the Vault server's audit subsystem (vault/audit, vault/vault, vault/builtin packages), which is not imported or executed by any Red Hat product.
    </Statement>
    <Mitigation xml:lang="en:us">
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
    </Mitigation>
    <PackageState cpe="cpe:/a:redhat:openshift:4">
        <ProductName>Red Hat OpenShift Container Platform 4</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>openshift4/ose-baremetal-installer-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift:4">
        <ProductName>Red Hat OpenShift Container Platform 4</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>openshift4/ose-installer-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_data_foundation:4">
        <ProductName>Red Hat Openshift Data Foundation 4</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>odf4/cephcsi-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_data_foundation:4">
        <ProductName>Red Hat Openshift Data Foundation 4</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>odf4/mcg-cli-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_data_foundation:4">
        <ProductName>Red Hat Openshift Data Foundation 4</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>odf4/mcg-rhel9-operator</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_data_foundation:4">
        <ProductName>Red Hat Openshift Data Foundation 4</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>odf4/odf-cli-rhel9</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-5051
https://nvd.nist.gov/vuln/detail/CVE-2026-5051
https://discuss.hashicorp.com/t/hcsec-2026-16-vault-audit-device-plugin-directory-guard-bypass-via-legacy-path-option/77536
    </References>
</Vulnerability>