CVE-2024-2048: Hashicorp Vault

Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Vault and Vault Enterprise (“Vault”) TLS certificate auth method did not correctly validate client certificates when configured with a non-CA certificate as trusted certificate. In this configuration, an attacker may be able to craft a malicious certificate that could be used to bypass authentication. Fixed in Vault 1.15.5 and 1.14.10.

Affected products

  • Hashicorp Vault: before 1.14.10 (fixed in 1.14.10); from 1.15.0, before 1.15.5 (fixed in 1.15.5)
  • Openbao Openbao: before 2.0.0 (fixed in 2.0.0)

Published 2024-03-04. Last modified 2026-06-17.