VaultGHSA-rr8j-7w34-xp5j
Vault Community Edition privilege escalation vulnerability
High7.2CVE-2024-9180 · Published Oct 10, 2024 · updated Jul 27, 2026
A privileged Vault operator with write permissions to the root namespace’s identity endpoint could escalate their privileges to Vault’s root policy. Fixed in Vault Community Edition 1.18.0 and Vault Enterprise 1.18.0, 1.17.7, 1.16.11, and 1.15.16
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/openbao/openbao Go | < 2.0.3 | 2.0.3 |
| github.com/hashicorp/vault Go | < 1.18.0 | 1.18.0 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-266
- Also known as
- BIT-openbao-2024-9180, BIT-vault-2024-9180, CVE-2024-9180, GO-2024-3191
More Vault advisories
All Vault| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 22025 | Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information | Medium4.5 | 1.19.3 |
| Oct 312024 | Hashicorp Vault vulnerable to denial of service through memory exhaustion | High7.5 | 1.18.1+1 more |
| Sep 22024 | Vault Leaks Client Token and Token Accessor in Audit Devices | Medium6.5 | 1.17.5 |
| Jul 112024 | Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions | High7.5 | 1.15.12+2 more |
| Jun 122024 | HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims | Low2.6 | 1.15.9+2 more |
| Apr 42024 | HashiCorpVault does not correctly validate OCSP responses | Medium6.4 | 1.16.0 |