Skip to content
VaultGHSA-9g4h-h484-3578

HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass

High8.1CVE-2025-11621 · Published Oct 23, 2025 · updated Sep 10, 2026

Vault and Vault Enterprise's ("Vault") AWS Auth method may be susceptible to authentication bypass if the role of the configured bound_principal_iam is the same across AWS accounts, or uses a wildcard. This vulnerability is fixed in Vault Community Edition 1.21.0 and Vault Enterprise 1.21.0, 1.20.5, 1.19.11, and 1.16.27.

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/hashicorp/vault
Go
>= 0.6.0, < 1.21.01.21.0
Details and references

More Vault advisories

All Vault

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.