Improper Certificate Validation in Vault Enterprise and Vault - CVE-2025-6037
Published: August 5, 2025
Vulnerability details
The vulnerability allows a remote attacker to impersonate other application users.
The vulnerability exists due to the application does not correctly validate client certificates when configured with a non-CA certificate as trusted certificate. A remote attacker can craft a malicious certificate that could be used to impersonate another user.
Affected software
Vault
How to mitigate CVE-2025-6037
Vault - update to 1.20.1