vaultGHSA-6h4p-m86h-hhgh
Hashicorp Vault has Privilege Escalation Vulnerability
High7.2CVE-2025-5999 · Published Aug 1, 2025 · updated Sep 10, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/vault Go | >= 0.10.4, < 1.20.0 | 1.20.0 |
Details and references
A privileged Vault operator with write permissions to the root namespace’s identity endpoint could escalate their own or another user’s token privileges to Vault’s root policy. Fixed in Vault Community Edition 1.20.0 and Vault Enterprise 1.20.0, 1.19.6, 1.18.11 and 1.16.22.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-266
- Also known as
- BIT-vault-2025-5999, CVE-2025-5999, GO-2025-3837
More vault advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 12025 | Hashicorp Vault has Incorrect Validation for Non-CA Certificates CVE-2025-6037Medium6.8fixed in 1.20.1 | Medium6.8 | 1.20.1 |
| Aug 12025 | Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration CVE-2025-6000Critical9.1fixed in 1.20.1 | Critical9.1 | 1.20.1 |
| Aug 12025 | Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users CVE-2025-6011Low3.7fixed in 1.20.1 | Low3.7 | 1.20.1 |
| Aug 12025 | Hashicorp Vault has Lockout Feature Authentication Bypass CVE-2025-6004Medium5.3fixed in 1.20.1 | Medium5.3 | 1.20.1 |
| Aug 12025 | Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse CVE-2025-6014Medium6.5fixed in 1.20.1 | Medium6.5 | 1.20.1 |
| Aug 12025 | Hashicorp Vault has Login MFA Rate Limit Bypass Vulnerability CVE-2025-6015Medium5.7fixed in 1.20.1 | Medium5.7 | 1.20.1 |