CVE-2025-5999High· 7.2▾ TwilightHashicorp Vault has Privilege Escalation Vulnerability
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.6 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.5%
0.5% → 0.5%
A privileged Vault operator with write permissions to the root namespace’s identity endpoint could escalate their own or another user’s token privileges to Vault’s root policy. Fixed in Vault Community Edition 1.20.0 and Vault Enterprise 1.20.0, 1.19.6, 1.18.11 and 1.16.22.
github.com/hashicorp/vault >= 0.10.4, < 1.20.0Upgrade to a patched release:
github.com/hashicorp/vault 1.20.0Connected by shared product, vendor, weakness, or advisory.
CVE-2023-5077High· 7.6Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability
CVE-2025-6013Medium· 6.5HashiCorp Vault ldap auth method may not have correctly enforced MFA
CVE-2025-6037Medium· 6.8Hashicorp Vault has Incorrect Validation for Non-CA Certificates
CVE-2023-5954High· 7.5HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability
CVE-2024-6468High· 7.5Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions
CVE-2023-4680Medium· 6.8HashiCorp Vault Improper Input Validation vulnerability