CVE-2026-4525
ADVISORY - githubSummary
If a Vault auth mount is configured to pass through the "Authorization" header, and the "Authorization" header is used to authenticate to Vault, Vault forwarded the Vault token to the auth plugin backend. Fixed in 2.0.0, 1.21.5, 1.20.10, and 1.19.16.
EPSS Score: 0.00026 (0.077)
Common Weakness Enumeration (CWE)
ADVISORY - nist
Insertion of Sensitive Information Into Sent Data
ADVISORY - github
Insertion of Sensitive Information Into Sent Data
ADVISORY - redhat
Insertion of Sensitive Information Into Sent Data
NIST
CREATED
UPDATED
ADVISORY IDCVE-2026-4525
EXPLOITABILITY SCORE
1.6
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)
CVSS SCORE
7.5highGitHub
CREATED
UPDATED
ADVISORY IDGHSA-72gw-fmmr-c4r4
EXPLOITABILITY SCORE
1.6
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)
CVSS SCORE
7.5highBitnami
CREATED
UPDATED
ADVISORY ID
BIT-vault-2026-4525
EXPLOITABILITY SCORE
2.8
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
8.8highRed Hat
CREATED
UPDATED
ADVISORY IDCVE-2026-4525
EXPLOITABILITY SCORE
1.6
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)
CVSS SCORE
7.5highminimos
CREATED
UPDATED
ADVISORY ID
MINI-5wqq-hrmf-2h3f
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
minimos
CREATED
UPDATED
ADVISORY ID
MINI-pfj3-7m8v-mhgw
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-