#VU113655 Improper Certificate Validation in Vault and Vault Enterprise - CVE-2025-6037
Published: August 5, 2025
Vault
Vault Enterprise
HashiCorp
Description
The vulnerability allows a remote attacker to impersonate other application users.
The vulnerability exists due to the application does not correctly validate client certificates when configured with a non-CA certificate as trusted certificate. A remote attacker can craft a malicious certificate that could be used to impersonate another user.