Improper Authentication in Vault Enterprise and Vault - CVE-2025-6015
Published: August 6, 2025
Vulnerability details
The vulnerability allows a remote user to bypass 2FA authentication.
The vulnerability exists due to the application does not properly normalize TOTP codes prior to enforcing the once-per-validity-window check. A remote attacker with knowledge of victim;s credentials can resubmit a previously used code during the MFA check and bypass MFA authentication.
Affected software
Vault
How to mitigate CVE-2025-6015
Vault - update to 1.20.1