Search
Find merged stories by title or summary.
cve-2026-5006
Vault Vulnerable to Privilege Escalation via Slash Injection in Templated Policy Paths
CVE-2026-5006 - Vault Vulnerable to Privilege Escalation via Slash Injection in Templated Policy Paths
CVE ID : CVE-2026-5006 Published : Aug. 24, 2026, 8:32 p. m. • 39 minutes ago Description : A vulnerability was identified in HashiCorp Vault and Vault Enterprise (“Vault”) such that an authenticated attacker may manipulate an identity value referenced by a templated policy path to gain unintended access to Vault paths. An attacker who can control the referenced identity value may include slash ({{/}}) characters that Vault interprets as additional path segments when rendering the policy. This vulnerability, CVE-2026-5006, was fixed in Vault Community Edition 2. 0. 4 and Vault Enterprise 2. 0. 4, 1. 21. 9, 1. 20. 14, and 1. 19. 20. Severity: 6.8 • MEDIUM
Siemens Solid Edge
View CSAF Summary Solid Edge is affected by multiple file parsing vulnerabilities that could be triggered when the application reads specially crafted files in PAR, PSM or DFT format. This could allow an attacker to crash the application or execute arbitrary code. Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens Solid Edge are affected: Solid Edge SE2025 vers:intdot/225. 0. 15 (CVE-2026-50058, CVE-2026-50059, CVE-2026-50060, CVE-2026-50061, CVE-2026-50062, CVE-2026-50063, CVE-2026-50064) Solid Edge SE2026 vers:intdot/226. 0.
You've reached the end of current stories for this search.
