Authentication Bypass in Vault and Vault Enterprise by HashiCorp
CVE-2025-11621

8.1HIGH

Key Information:

Vendor

Hashicorp

Vendor
CVE Published:
23 October 2025

What is CVE-2025-11621?

The AWS Auth method within Vault and Vault Enterprise is vulnerable to an authentication bypass due to improper handling of IAM roles when the configured bound_principal_iam role is identical across multiple AWS accounts or uses a wildcard. This weakness could allow attackers to exploit the authentication mechanism and gain unauthorized access to sensitive resources. Users are advised to upgrade to the patched versions of Vault to mitigate potential risks associated with this vulnerability.

Affected Version(s)

Vault 64 bit 0.6.0 < 1.21.0

Vault Enterprise 64 bit 0.6.0 < 1.21.0

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-11621 : Authentication Bypass in Vault and Vault Enterprise by HashiCorp