Permissions, Privileges, and Access Controls in Vault Enterprise and Vault - CVE-2025-5999
Published: August 6, 2025
Vulnerability details
The vulnerability allows a remote user to escalate privileges within the application.
The vulnerability exists due to application does not properly impose security restrictions. A privileged Vault operator with write permissions to the root namespace’s identity endpoint can escalate their own or another user’s token privileges to Vault’s root policy.
Affected software
Vault
How to mitigate CVE-2025-5999
Vault - update to 1.20.0