Authentication bypass using an alternate path or channel in Vault Enterprise and Vault - CVE-2025-11621
Published: October 24, 2025 / Updated: November 25, 2025
Vulnerability identifier: #VU117641
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-11621
CWE-ID: CWE-288
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to the authentication bypass using an alternate path or channel within AWS Auth method. A remote user can gain acces to sensitive data and potentially gain elevated privileges.
Affected software
Vault Enterprise
Vault
Trusted Artifact Signer (RHTAS)
Vault
Trusted Artifact Signer (RHTAS)
How to mitigate CVE-2025-11621
Install updates from vendor's website.
Vault Enterprise - addressed in versions 1.16.27, 1.19.11, 1.20.5, 1.21.0
Vault - update to 1.21.0
Trusted Artifact Signer (RHTAS) - update to 1.3.1
Vault - update to 1.21.0
Trusted Artifact Signer (RHTAS) - update to 1.3.1