Known vulnerabilities in Vault Enterprise

Vendor: HashiCorp
Software CPE: cpe:2.3:a:hashicorp:vault_enterprise:*:*:*:*:*:*:*:*
Total vulnerabilities: 69
Public exploits: 1
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Vault Enterprise Vault Enterprise is affected by 69 known vulnerabilities: 3 high, 37 medium, 29 low Critical High Medium Low

Vulnerabilities (69)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU145119 - Improper Authorization
CVE-2026-5006
CWE-285 Low
No
No
1.19.20, 1.20.14, 1.21.9, 2.0.4 25.08.2026 SB2026082533
#VU141396 - Improper Authorization
CVE-2026-12624
CWE-285 Low
No
No
1.19.19, 1.20.13, 1.21.8, 2.0.3 11.08.2026 SB2026081127
#VU141395 - Improper Access Control
CVE-2026-14886
CWE-284 Low
No
No
1.19.20, 1.20.14, 1.21.9, 2.0.4 11.08.2026 SB2026081126
#VU136683 - Improper Access Control
CVE-2026-5051
CWE-284 Low
No
No
1.19.17, 1.20.11, 1.21.6, 2.0.1 02.07.2026 SB2026070222
#VU126410 - Server-Side Request Forgery (SSRF)
CVE-2026-5052
CWE-918 Medium
No
No
1.19.16, 1.20.10, 1.21.5, 2.0.0 17.04.2026 SB2026041755
#VU126409 - Exposure of sensitive information to an unauthorized actor
CVE-2026-4525
CWE-200 Low
No
No
1.19.16, 1.20.10, 1.21.5, 2.0.0 17.04.2026 SB2026041755
#VU126408 - Missing Authentication for Critical Function
CVE-2026-5807
CWE-306 Medium
No
No
1.19.16, 1.20.10, 1.21.5, 2.0.0 17.04.2026 SB2026041755
#VU126407 - Improper Access Control
CVE-2026-3605
CWE-284 Low
No
No
1.19.16, 1.20.10, 1.21.5, 2.0.0 17.04.2026 SB2026041755
#VU117644 - Allocation of Resources Without Limits or Throttling
CVE-2025-12044
CWE-770 Medium
No
No
1.16.27, 1.19.11, 1.20.5, 1.21.0 24.10.2025 SB2025102442
SB2025112573
#VU117641 - Authentication Bypass Using an Alternate Path or Channel
CVE-2025-11621
CWE-288 Medium
No
No
1.16.27, 1.19.11, 1.20.5, 1.21.0 24.10.2025 SB2025102442
SB2025112573
#VU114572 - Resource exhaustion
CVE-2025-6203
CWE-400 Medium
No
No
1.16.25, 1.18.14, 1.19.9, 1.20.3 30.08.2025 SB2025083003
#VU113697 - Permissions, Privileges, and Access Controls
CVE-2025-5999
CWE-264 Low
No
No
1.16.22, 1.18.11, 1.19.6, 1.20.0 06.08.2025 SB2025062527
#VU113695 - Improper Authentication
CVE-2025-6013
CWE-287 Medium
No
No
1.16.24, 1.18.13, 1.19.8, 1.20.2 06.08.2025 SB2025080621
#VU113692 - Improper Authentication
CVE-2025-6014
CWE-287 Medium
No
No
1.16.23, 1.18.12, 1.19.7, 1.20.1 06.08.2025 SB2025080578
#VU113691 - Improper Authentication
CVE-2025-6015
CWE-287 Low
No
No
1.16.23, 1.18.12, 1.19.7, 1.20.1 06.08.2025 SB2025080578
#VU113690 - Protection Mechanism Failure
CVE-2025-6004
CWE-693 Low
No
No
1.16.23, 1.18.12, 1.19.7, 1.20.1 06.08.2025 SB2025080578
#VU113655 - Improper Certificate Validation
CVE-2025-6037
CWE-295 Medium
No
No
1.16.23, 1.18.12, 1.19.7, 1.20.1 05.08.2025 SB2025080578
#VU113654 - Information Exposure Through Timing Discrepancy
CVE-2025-6011
CWE-208 Low
No
No
1.16.23, 1.18.12, 1.19.7, 1.20.1 05.08.2025 SB2025080578
#VU113653 - Permissions, Privileges, and Access Controls
CVE-2025-6000
CWE-264 Low
No
No
1.16.23, 1.18.12, 1.19.7, 1.20.1 05.08.2025 SB2025080578
#VU111942 - Resource Management Errors
CVE-2025-4656
CWE-399 Medium
No
No
1.16.22, 1.17.17, 1.18.11, 1.19.6, 1.20.0 25.06.2025 SB2025062527


Showing elements 1 - 20 out of 69