Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-5807

29
FAUCET Score

CVE-2026-5807 is a denial-of-service vulnerability affecting HashiCorp Vault that allows unauthenticated attackers to disrupt critical administrative operations by repeatedly initiating or canceling root token generation and rekey procedures. By occupying the single available in-progress operation slot, attackers can prevent legitimate operators from completing essential security workflows. This vulnerability affects Vault Community Edition and Vault Enterprise versions prior to 2.0.0. The vulnerability carries a CVSS score of 7.5 (HIGH) with a network-based attack vector requiring no authentication, low attack complexity, and no user interaction. The impact is strictly limited to availability, with no confidentiality or integrity compromise possible. The EPSS score of 0.000180000 indicates low predicted exploitation probability relative to the broader CVE landscape. There is no evidence of active exploitation or publicly available exploit code at this time. The vulnerability is not listed on the CISA Known Exploited Vulnerabilities catalog and remains inactive on threat intelligence hotlists. Organizations should apply the available patches for Vault 2.0.0 or later during normal maintenance windows, though the immediate exploitation risk appears minimal based on current threat indicators.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.0.0CPE matchmatch criteria
cpe:2.3:a:hashicorp:vault:*:*:*:*:-:*:*:*
< 2.0.0CPE matchmatch criteria
cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.72%
Probability of exploitation in next 30 days
EPSS Percentile
50.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0072 is in the 26th percentile among its peer group of 51,553 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

goGHSA-88v5-9hxc-f85rhigh

HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations

Apr 17, 2026

References

access.redhat.com / security/cve/CVE-2026-5807
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-5807.json
discuss.hashicorp.com / t/hcsec-2026-08-vault-vulnerable-to-denial-of-service-via-unauthenticated-root-token-generation-rekey-operations/77345
Vendor Advisory