VaultGHSA-9g4h-h484-3578
HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass
High8.1CVE-2025-11621 · Published Oct 23, 2025 · updated Sep 10, 2026
Vault and Vault Enterprise's ("Vault") AWS Auth method may be susceptible to authentication bypass if the role of the configured bound_principal_iam is the same across AWS accounts, or uses a wildcard. This vulnerability is fixed in Vault Community Edition 1.21.0 and Vault Enterprise 1.21.0, 1.20.5, 1.19.11, and 1.16.27.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/vault Go | >= 0.6.0, < 1.21.0 | 1.21.0 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-288
- Also known as
- BIT-vault-2025-11621, CVE-2025-11621, GO-2025-4070
More Vault advisories
All Vault| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Oct 232025 | Hashicorp Vault and Vault Enterprise vulnerable to a denial of service when processing JSON | High7.5 | 1.21.0 |
| Aug 282025 | HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads | High7.5 | 1.20.3 |
| Aug 62025 | HashiCorp Vault ldap auth method may not have correctly enforced MFA | Medium6.5 | 1.20.2 |
| Aug 12025 | Hashicorp Vault has Incorrect Validation for Non-CA Certificates | Medium6.8 | 1.20.1 |
| Aug 12025 | Hashicorp Vault has Privilege Escalation Vulnerability | High7.2 | 1.20.0 |
| Aug 12025 | Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration | Critical9.1 | 1.20.1 |