CVE-2025-5999

EUVD-2025-23388
A privileged Vault operator with write permissions to the root namespace’s identity endpoint could escalate their own or another user’s token privileges to Vault’s root policy. Fixed in Vault Community Edition 1.20.0 and Vault Enterprise 1.20.0, 1.19.6, 1.18.11 and 1.16.22.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
hashicorpvault
0.10.4 ≤
𝑥
< 1.16.22
hashicorpvault
0.10.4 ≤
𝑥
< 1.20.0
hashicorpvault
1.17.0 ≤
𝑥
< 1.18.11
hashicorpvault
1.19.0 ≤
𝑥
< 1.19.6
𝑥
= Vulnerable software versions