216.73.217.22

CVE-2025-11621

· Published 23/10/2025 19:15 · Modified 23/10/2025 19:15

Labels: CVE-2025-11621 2025-10-23CVE-2025-11621CWE-288[email protected]

Essential information

Published
23/10/2025 19:15
Modified
23/10/2025 19:15
Author
Creator
CVSS
8.1 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

CVSS metrics

Description

Vault and Vault Enterprise’s (“Vault”) AWS Auth method may be susceptible to authentication bypass if the role of the configured bound_principal_iam is the same across AWS accounts, or uses a wildcard. This vulnerability, CVE-2025-11621, is fixed in Vault Community Edition 1.21.0 and Vault Enterprise 1.21.0, 1.20.5, 1.19.11, and 1.16.27

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
hashicorp / vault cpe:2.3:a:hashicorp:vault:1.21.0:*:*:*:*:*:*:*
hashicorp / vault cpe:2.3:a:hashicorp:vault:1.20.5:*:*:*:*:*:*:*
hashicorp / vault cpe:2.3:a:hashicorp:vault:1.19.11:*:*:*:*:*:*:*
hashicorp / vault cpe:2.3:a:hashicorp:vault:1.16.27:*:*:*:*:*:*:*

References