#VU113691 Improper Authentication in Vault and Vault Enterprise - CVE-2025-6015
Published: August 6, 2025
Vault
Vault Enterprise
HashiCorp
Description
The vulnerability allows a remote user to bypass 2FA authentication.
The vulnerability exists due to the application does not properly normalize TOTP codes prior to enforcing the once-per-validity-window check. A remote attacker with knowledge of victim;s credentials can resubmit a previously used code during the MFA check and bypass MFA authentication.