Authentication Bypass in Vault and Vault Enterprise by HashiCorp
CVE-2025-11621
What is CVE-2025-11621?
The AWS Auth method within Vault and Vault Enterprise is vulnerable to an authentication bypass due to improper handling of IAM roles when the configured bound_principal_iam role is identical across multiple AWS accounts or uses a wildcard. This weakness could allow attackers to exploit the authentication mechanism and gain unauthorized access to sensitive resources. Users are advised to upgrade to the patched versions of Vault to mitigate potential risks associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Vault 64 bit 0.6.0 < 1.21.0
Vault Enterprise 64 bit 0.6.0 < 1.21.0
News Articles
References
CVSS V3.1
Timeline
- ๐ฐ
First article discovered by CybersecurityNews
Vulnerability published
Vulnerability Reserved