CVE-2026-5807 is a denial-of-service vulnerability affecting HashiCorp Vault that allows unauthenticated attackers to disrupt critical administrative operations by repeatedly initiating or canceling root token generation and rekey procedures. By occupying the single available in-progress operation slot, attackers can prevent legitimate operators from completing essential security workflows. This vulnerability affects Vault Community Edition and Vault Enterprise versions prior to 2.0.0. The vulnerability carries a CVSS score of 7.5 (HIGH) with a network-based attack vector requiring no authentication, low attack complexity, and no user interaction. The impact is strictly limited to availability, with no confidentiality or integrity compromise possible. The EPSS score of 0.000180000 indicates low predicted exploitation probability relative to the broader CVE landscape. There is no evidence of active exploitation or publicly available exploit code at this time. The vulnerability is not listed on the CISA Known Exploited Vulnerabilities catalog and remains inactive on threat intelligence hotlists. Organizations should apply the available patches for Vault 2.0.0 or later during normal maintenance windows, though the immediate exploitation risk appears minimal based on current threat indicators.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.0.0CPE matchmatch criteria | cpe:2.3:a:hashicorp:vault:*:*:*:*:-:*:*:* | ||
< 2.0.0CPE matchmatch criteria | cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.