← Back

Vault

vault

Vendor: Hashicorp • 72 CVEs

CVEs (72)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hashicorp
1Vault
Jun 17, 2026
Mar 11, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
HashiCorp Vault and Vault Enterprise’s approle auth method allowed any authenticated user with access to an approle destroy endpoint to destroy the secret ID of any other role by providing the secret ID accessor. This vu...Show more
HashiCorp Vault and Vault Enterprise’s approle auth method allowed any authenticated user with access to an approle destroy endpoint to destroy the secret ID of any other role by providing the secret ID accessor. This vulnerability is fixed in Vault 1.13.0, 1.12.4, 1.11.8, 1.10.11 and above.Show less
1Hashicorp
1Vault
Jun 17, 2026
Oct 12, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
HashiCorp Vault and Vault Enterprise’s TLS certificate auth method did not initially load the optionally configured CRL issued by the role's CA into memory on startup, resulting in the revocation list not being checked i...Show more
HashiCorp Vault and Vault Enterprise’s TLS certificate auth method did not initially load the optionally configured CRL issued by the role's CA into memory on startup, resulting in the revocation list not being checked if the CRL has not yet been retrieved. Fixed in 1.12.0, 1.11.4, 1.10.7, and 1.9.10.Show less
1Hashicorp
1Vault
Jun 17, 2026
Sep 22, 2022
N/A· v4
9.1 CRITICAL· v3
N/A· v2
An issue was discovered in HashiCorp Vault and Vault Enterprise before 1.11.3. A vulnerability in the Identity Engine was found where, in a deployment where an entity has multiple mount accessors with shared alias names,...Show more
An issue was discovered in HashiCorp Vault and Vault Enterprise before 1.11.3. A vulnerability in the Identity Engine was found where, in a deployment where an entity has multiple mount accessors with shared alias names, Vault may overwrite metadata to the wrong alias due to an issue with checking the proper alias assigned to an entity. This may allow for unintended access to key/value paths using that metadata in Vault.Show less
1Hashicorp
1Vault
Jun 17, 2026
Jul 26, 2022
N/A· v4
9.1 CRITICAL· v3
N/A· v2
HashiCorp Vault Enterprise 1.7.0 through 1.9.7, 1.10.4, and 1.11.0 clusters using Integrated Storage expose an unauthenticated API endpoint that could be abused to override the voter status of a node within a Vault HA cl...Show more
HashiCorp Vault Enterprise 1.7.0 through 1.9.7, 1.10.4, and 1.11.0 clusters using Integrated Storage expose an unauthenticated API endpoint that could be abused to override the voter status of a node within a Vault HA cluster, introducing potential for future data loss or catastrophic failure. Fixed in Vault Enterprise 1.9.8, 1.10.5, and 1.11.1.Show less
1Hashicorp
1Vault
Jun 17, 2026
May 17, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
HashiCorp Vault and Vault Enterprise from 1.10.0 to 1.10.2 did not correctly configure and enforce MFA on login after server restarts. This affects the Login MFA feature introduced in Vault and Vault Enterprise 1.10.0 an...Show more
HashiCorp Vault and Vault Enterprise from 1.10.0 to 1.10.2 did not correctly configure and enforce MFA on login after server restarts. This affects the Login MFA feature introduced in Vault and Vault Enterprise 1.10.0 and does not affect the separate Enterprise MFA feature set. Fixed in 1.10.3.Show less
1Hashicorp
1Vault
Jun 17, 2026
Mar 10, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Vault Enterprise clusters using the tokenization transform feature can expose the tokenization key through the tokenization key configuration endpoint to authorized operators with `read` permissions on this endpoint. Fix...Show more
Vault Enterprise clusters using the tokenization transform feature can expose the tokenization key through the tokenization key configuration endpoint to authorized operators with `read` permissions on this endpoint. Fixed in Vault Enterprise 1.9.4, 1.8.9 and 1.7.10.Show less
1Hashicorp
1Vault
Jun 17, 2026
Mar 10, 2022
N/A· v4
6.5 MEDIUM· v3
3.5 LOW· v2
"Vault and Vault Enterprise 1.8.0 through 1.8.8, and 1.9.3 allowed the PKI secrets engine under certain configurations to issue wildcard certificates to authorized users for a specified domain, even if the PKI role polic...Show more
"Vault and Vault Enterprise 1.8.0 through 1.8.8, and 1.9.3 allowed the PKI secrets engine under certain configurations to issue wildcard certificates to authorized users for a specified domain, even if the PKI role policy attribute allow_subdomains is set to false. Fixed in Vault Enterprise 1.8.9 and 1.9.4.Show less
1Hashicorp
1Vault
Jun 17, 2026
Dec 17, 2021
N/A· v4
4.9 MEDIUM· v3
6.8 MEDIUM· v2
In HashiCorp Vault and Vault Enterprise before 1.7.7, 1.8.x before 1.8.6, and 1.9.x before 1.9.1, clusters using the Integrated Storage backend allowed an authenticated user (with write permissions to a kv secrets engine...Show more
In HashiCorp Vault and Vault Enterprise before 1.7.7, 1.8.x before 1.8.6, and 1.9.x before 1.9.1, clusters using the Integrated Storage backend allowed an authenticated user (with write permissions to a kv secrets engine) to cause a panic and denial of service of the storage backend. The earliest affected version is 1.4.0.Show less
1Hashicorp
1Vault
Jun 17, 2026
Nov 30, 2021
N/A· v4
6.5 MEDIUM· v3
5.5 MEDIUM· v2
HashiCorp Vault and Vault Enterprise 0.11.0 up to 1.7.5 and 1.8.4 templated ACL policies would always match the first-created entity alias if multiple entity aliases exist for a specified entity and mount combination, po...Show more
HashiCorp Vault and Vault Enterprise 0.11.0 up to 1.7.5 and 1.8.4 templated ACL policies would always match the first-created entity alias if multiple entity aliases exist for a specified entity and mount combination, potentially resulting in incorrect policy enforcement. Fixed in Vault and Vault Enterprise 1.7.6, 1.8.5, and 1.9.0.Show less
1Hashicorp
1Vault
Jun 17, 2026
Oct 11, 2021
N/A· v4
8.1 HIGH· v3
4.9 MEDIUM· v2
HashiCorp Vault and Vault Enterprise 1.8.x through 1.8.4 may have an unexpected interaction between glob-related policies and the Google Cloud secrets engine. Users may, in some situations, have more privileges than inte...Show more
HashiCorp Vault and Vault Enterprise 1.8.x through 1.8.4 may have an unexpected interaction between glob-related policies and the Google Cloud secrets engine. Users may, in some situations, have more privileges than intended, e.g., a user with read permission for the /gcp/roleset/* path may be able to issue Google Cloud service account credentials.Show less
1Hashicorp
1Vault
Jun 17, 2026
Oct 8, 2021
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
HashiCorp Vault and Vault Enterprise through 1.7.4 and 1.8.3 allowed a user with write permission to an entity alias ID sharing a mount accessor with another user to acquire this other user’s policies by merging their id...Show more
HashiCorp Vault and Vault Enterprise through 1.7.4 and 1.8.3 allowed a user with write permission to an entity alias ID sharing a mount accessor with another user to acquire this other user’s policies by merging their identities. Fixed in Vault and Vault Enterprise 1.7.5 and 1.8.4.Show less
1Hashicorp
1Vault
Jun 17, 2026
Aug 31, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
HashiCorp Vault Enterprise 0.9.2 through 1.6.2 allowed the read of license metadata from DR secondaries without authentication. Fixed in 1.6.3.
1Hashicorp
1Vault
Jun 17, 2026
Aug 13, 2021
N/A· v4
5.3 MEDIUM· v3
3.5 LOW· v2
HashiCorp Vault and Vault Enterprise’s UI erroneously cached and exposed user-viewed secrets between sessions in a single shared browser. Fixed in 1.8.0 and pending 1.7.4 / 1.6.6 releases.
1Hashicorp
1Vault
Jun 17, 2026
Aug 13, 2021
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
HashiCorp Vault and Vault Enterprise 1.4.0 through 1.7.3 initialized an underlying database file associated with the Integrated Storage feature with excessively broad filesystem permissions. Fixed in Vault and Vault Ente...Show more
HashiCorp Vault and Vault Enterprise 1.4.0 through 1.7.3 initialized an underlying database file associated with the Integrated Storage feature with excessively broad filesystem permissions. Fixed in Vault and Vault Enterprise 1.8.0.Show less
1Hashicorp
1Vault
Jun 17, 2026
Jun 3, 2021
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
HashiCorp Vault and Vault Enterprise allowed the renewal of nearly-expired token leases and dynamic secret leases (specifically, those within 1 second of their maximum TTL), which caused them to be incorrectly treated as...Show more
HashiCorp Vault and Vault Enterprise allowed the renewal of nearly-expired token leases and dynamic secret leases (specifically, those within 1 second of their maximum TTL), which caused them to be incorrectly treated as non-expiring during subsequent use. Fixed in 1.5.9, 1.6.5, and 1.7.2.Show less
1Hashicorp
1Vault
Jun 17, 2026
Apr 22, 2021
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
HashiCorp Vault and Vault Enterprise 1.5.1 and newer, under certain circumstances, may exclude revoked but unexpired certificates from the CRL. Fixed in 1.5.8, 1.6.4, and 1.7.1.
1Hashicorp
1Vault
Jun 17, 2026
Apr 22, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
HashiCorp Vault and Vault Enterprise Cassandra integrations (storage backend and database secrets engine plugin) did not validate TLS certificates when connecting to Cassandra clusters. Fixed in 1.6.4 and 1.7.1
1Hashicorp
1Vault
Jun 17, 2026
Feb 1, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
HashiCorp Vault Enterprise 1.6.0 & 1.6.1 allowed the `remove-peer` raft operator command to be executed against DR secondaries without authentication. Fixed in 1.6.2.
1Hashicorp
1Vault
Jun 17, 2026
Feb 1, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
HashiCorp Vault and Vault Enterprise disclosed the internal IP address of the Vault node when responding to some invalid, unauthenticated HTTP requests. Fixed in 1.6.2 & 1.5.7.
1Hashicorp
1Vault
Jun 17, 2026
Feb 1, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
HashiCorp Vault and Vault Enterprise allowed for enumeration of Secrets Engine mount paths via unauthenticated HTTP requests. Fixed in 1.6.2 & 1.5.7.