Skip to content
VaultGHSA-rr8j-7w34-xp5j

Vault Community Edition privilege escalation vulnerability

High7.2CVE-2024-9180 · Published Oct 10, 2024 · updated Jul 27, 2026

A privileged Vault operator with write permissions to the root namespace’s identity endpoint could escalate their privileges to Vault’s root policy. Fixed in Vault Community Edition 1.18.0 and Vault Enterprise 1.18.0, 1.17.7, 1.16.11, and 1.15.16

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/openbao/openbao
Go
< 2.0.32.0.3
github.com/hashicorp/vault
Go
< 1.18.01.18.0
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-266
Also known as
BIT-openbao-2024-9180, BIT-vault-2024-9180, CVE-2024-9180, GO-2024-3191

More Vault advisories

All Vault
Advisory
Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information
Medium4.5May 2, 2025
Hashicorp Vault vulnerable to denial of service through memory exhaustion
High7.5Oct 31, 2024
Vault Leaks Client Token and Token Accessor in Audit Devices
Medium6.5Sep 2, 2024
Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions
High7.5Jul 11, 2024
HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims
Low2.6Jun 12, 2024
HashiCorpVault does not correctly validate OCSP responses
Medium6.4Apr 4, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.