Authentication Bypass in Vault and Vault Enterprise by HashiCorp
CVE-2025-11621
8.1HIGH
What is CVE-2025-11621?
The AWS Auth method within Vault and Vault Enterprise is vulnerable to an authentication bypass due to improper handling of IAM roles when the configured bound_principal_iam role is identical across multiple AWS accounts or uses a wildcard. This weakness could allow attackers to exploit the authentication mechanism and gain unauthorized access to sensitive resources. Users are advised to upgrade to the patched versions of Vault to mitigate potential risks associated with this vulnerability.
Affected Version(s)
Vault 64 bit 0.6.0 < 1.21.0
Vault Enterprise 64 bit 0.6.0 < 1.21.0