Skip to content
vaultGHSA-6h4p-m86h-hhgh

Hashicorp Vault has Privilege Escalation Vulnerability

High7.2CVE-2025-5999 · Published Aug 1, 2025 · updated Sep 10, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/hashicorp/vault
Go
>= 0.10.4, < 1.20.01.20.0
Details and references

A privileged Vault operator with write permissions to the root namespace’s identity endpoint could escalate their own or another user’s token privileges to Vault’s root policy. Fixed in Vault Community Edition 1.20.0 and Vault Enterprise 1.20.0, 1.19.6, 1.18.11 and 1.16.22.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-266
Also known as
BIT-vault-2025-5999, CVE-2025-5999, GO-2025-3837

More vault advisories

All
DateAdvisory
Aug 12025Hashicorp Vault has Incorrect Validation for Non-CA Certificates
CVE-2025-6037Medium6.8fixed in 1.20.1
Aug 12025Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration
CVE-2025-6000Critical9.1fixed in 1.20.1
Aug 12025Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users
CVE-2025-6011Low3.7fixed in 1.20.1
Aug 12025Hashicorp Vault has Lockout Feature Authentication Bypass
CVE-2025-6004Medium5.3fixed in 1.20.1
Aug 12025Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse
CVE-2025-6014Medium6.5fixed in 1.20.1
Aug 12025Hashicorp Vault has Login MFA Rate Limit Bypass Vulnerability
CVE-2025-6015Medium5.7fixed in 1.20.1

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.