Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-5807

Опубликовано: 17 апр. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Vault is vulnerable to a denial-of-service condition where an unauthenticated attacker can repeatedly initiate or cancel root token generation or rekey operations, occupying the single in-progress operation slot. This prevents legitimate operators from completing these workflows. This vulnerability, CVE-2026-5807, is fixed in Vault Community Edition 2.0.0 and Vault Enterprise 2.0.0.

A flaw was found in Vault. An unauthenticated attacker can repeatedly initiate or cancel root token generation or rekey operations. This action occupies the single slot designated for in-progress operations, effectively preventing legitimate operators from completing critical administrative workflows. This vulnerability leads to a denial-of-service condition, impacting the availability of Vault's key management functions.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 4openshift4/ose-baremetal-installer-rhel9Not affected
Red Hat OpenShift Container Platform 4openshift4/ose-installer-rhel9Not affected
Red Hat Openshift Data Foundation 4cephcsi-rhel8Not affected
Red Hat Openshift Data Foundation 4cephcsi-rhel9Not affected
Red Hat Openshift Data Foundation 4mcg-cli-rhel9Affected
Red Hat Openshift Data Foundation 4mcg-rhel8-operatorAffected
Red Hat Openshift Data Foundation 4mcg-rhel9-operatorAffected
Red Hat Openshift Data Foundation 4ocs4/cephcsi-rhel8Not affected
Red Hat Openshift Data Foundation 4odf4/cephcsi-rhel8Not affected
Red Hat Openshift Data Foundation 4odf4/cephcsi-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2459109Vault: Vault: Denial of Service via unauthenticated root token generation or rekey operations

EPSS

Процентиль: 49%
0.00718
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
4 месяца назад

Vault is vulnerable to a denial-of-service condition where an unauthenticated attacker can repeatedly initiate or cancel root token generation or rekey operations, occupying the single in-progress operation slot. This prevents legitimate operators from completing these workflows. This vulnerability, CVE-2026-5807, is fixed in Vault Community Edition 2.0.0 and Vault Enterprise 2.0.0.

CVSS3: 7.5
github
4 месяца назад

HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations

CVSS3: 7.5
fstec
4 месяца назад

Уязвимость платформ для архивирования корпоративной информации HashiCorp Vault Community Edition и Vault Enterprise, связанная с неограниченным распределением ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
redos
2 месяца назад

Уязвимость vault

EPSS

Процентиль: 49%
0.00718
Низкий

7.5 High

CVSS3