CVE-2026-4525
HashiCorp Vault, Vault Enterprise, Red Hat OpenShift Container Platform 4 취약점
If a Vault auth mount is configured to pass through the "Authorization" header, and the "Authorization" header is used to authenticate to Vault, Vault forwarded the Vault token to the auth plugin backend. Fixed in 2.0.0, 1.21.5, 1.20.10, and 1.19.16.
- 대응 우선순위
- 점검
- CVSS
- 8.8
- EPSS
- 0.41% 백분위 33.3% · 2026.08.04 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2026.04.17