Permissions, Privileges, and Access Controls in Vault Enterprise and Vault - CVE-2025-5999

 

Permissions, Privileges, and Access Controls in Vault Enterprise and Vault - CVE-2025-5999

Published: August 6, 2025


Vulnerability identifier: #VU113697
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2025-5999
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to escalate privileges within the application.

The vulnerability exists due to application does not properly impose security restrictions. A privileged Vault operator with write permissions to the root namespace’s identity endpoint can escalate their own or another user’s token privileges to Vault’s root policy.


Affected software

Vault Enterprise
Vault

How to mitigate CVE-2025-5999

Install updates from vendor's website.

Vault Enterprise - addressed in versions 1.16.22, 1.18.11, 1.19.6, 1.20.0
Vault - update to 1.20.0

External References

Related Security Bulletins