CVE Tools

Vault Enterprise

54 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Vault Enterprise, a product in the cloud saas space. Use it to gauge the current risk picture and drill into individual advisories.

Vault Enterprise CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Vault Enterprise CVEs per month
MonthCVEs
2024-102
2024-117
2024-120
2025-010
2025-020
2025-030
2025-040
2025-052
2025-061
2025-070
2025-089
2025-090
2025-102
2025-110
2025-120
2026-010
2026-020
2026-030
2026-044
2026-050
2026-060
2026-071
2026-083
2026-090

Severity

How the 54 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical917%
  • High1528%
  • Medium2648%
  • Low47%

Latest CVEs

The 15 most recently published vulnerabilities affecting Vault Enterprise.

  1. CVE-2026-5006Vault Vulnerable to Privilege Escalation via Slash Injection in Templated Policy Paths6.8
  2. CVE-2026-14886Vault Enterprise vulnerable to cross-namespace entity deletion8.2
  3. CVE-2026-12624Vault vulnerable to LIST authorization bypass via trailing-slash strip4.3
  4. CVE-2026-5051Audit Log Plugin Directory Guard Bypass via Legacy path Option4.4
  5. CVE-2026-5807Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations7.5
  6. CVE-2026-4525Vault Token Leaked to Backends via Authorization: Bearer Passthrough Header7.5
  7. CVE-2026-5052Vault Vulnerable to Server-Side Request Forgery in ACME Challenge Validation via Attacker-Controlled DNS5.3
  8. CVE-2026-3605Vault KVv2 Metadata and Secret Deletion Policy Bypass Denial-of-Service8.1
  9. CVE-2025-12044Vault Vulnerable to Denial of Service Due to Rate Limit Regression7.5
  10. CVE-2025-11621Vault AWS auth method bypass due to AWS client cache8.1
  11. CVE-2025-6203Vault unauthenticated denial of service through complex json payload7.5
  12. CVE-2025-6013Vault LDAP MFA Enforcement Bypass When Using Username As Alias6.5
  13. CVE-2025-6015Vault Login MFA Bypass of Rate Limiting and TOTP Code Reuse5.7
  14. CVE-2025-6011Timing Side-Channel in Vault’s Userpass Auth Method3.7
  15. CVE-2025-6004Vault Userpass and LDAP User Lockout Bypass5.3

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store