Sploitus

CVE-2026-5052

No indexed exploits for CVE-2026-5052 yet

Vault’s PKI engine’s ACME validation did not reject local targets when issuing http-01 and tls-alpn-01 challenges. This may lead to these requests being sent to local network targets, potentially leading to information disclosure. Fixed in Vault Community Edition 2.0.0 and Vault Enterprise 2.0.0, 1.21.5, 1.20.10, and 1.19.16.

Hashicorp Vault
< 1.19.16, 2.0.0, 1.20.10, 1.21.5
Fix
Available
CVSS 3.1
8.6 HIGH
EPSS
0.3% (26th percentile)
Weakness
CWE-918
NVD status
Analyzed
Published
2026-04-17
Attack patterns
CAPEC-118
CVE-2026-5052 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-5052 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-5052 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.