Protection Mechanism Failure in Vault Enterprise and Vault - CVE-2025-6004
Published: August 6, 2025
Vulnerability details
The vulnerability allows a remote user to bypass implemented security restrictions.
The vulnerability exists due to incorrect implementation of the user lockout mechanism. A remote user can bypass the user lockout feature for Userpass and LDAP authentication methods by varying the cases of characters in the user name when an auth method was not configured to be case sensitive.
Affected software
Vault
How to mitigate CVE-2025-6004
Vault - update to 1.20.1