#VU126408 Missing Authentication for Critical Function in Vault and Vault Enterprise - CVE-2026-5807
Published: April 17, 2026
Vault
Vault Enterprise
HashiCorp
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper access control in the sys/rekey, sys/generate-root, and sys/rekey-recovery-key endpoints when handling unauthenticated root token generation or rekey requests. A remote attacker can repeatedly initiate or cancel operations to cause a denial of service.
The issue can occupy the single in-progress operation slot and prevent legitimate operators from completing these workflows.