#VU126410 Server-Side Request Forgery (SSRF) in Vault and Vault Enterprise - CVE-2026-5052

 

#VU126410 Server-Side Request Forgery (SSRF) in Vault and Vault Enterprise - CVE-2026-5052

Published: April 17, 2026


Vulnerability identifier: #VU126410
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:U/U:Green
CVE-ID: CVE-2026-5052
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Vault
Vault Enterprise
Software vendor:
HashiCorp

Description

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper restriction of server-side request targets in the PKI engine ACME challenge validation when issuing http-01 and tls-alpn-01 challenges using attacker-controlled DNS. A remote attacker can cause Vault to send challenge validation requests to local network targets to disclose sensitive information.

Depending on the Vault configuration, the challenge endpoint is either unauthenticated or requires an EAB token.


Remediation

Install security update from vendor's website.

External links