CVE-2025-6013: Hashicorp Vault
High severity, CVSS 8.1. EPSS: 0.5% chance of exploitation in the next 30 days.
Vault and Vault Enterprise’s (“Vault”) ldap auth method may not have correctly enforced MFA if username_as_alias was set to true and a user had multiple CNs that are equal but with leading or trailing spaces. Fixed in Vault Community Edition 1.20.2 and Vault Enterprise 1.20.2, 1.19.8, 1.18.13, and 1.16.24.
Affected products
- Hashicorp Vault: from 1.10.0, up to and including 1.15.16; from 1.10.0, before 1.20.2 (fixed in 1.20.2); from 1.16.0, before 1.16.24 (fixed in 1.16.24); from 1.17.0, before 1.18.13 (fixed in 1.18.13); from 1.19.0, before 1.19.8 (fixed in 1.19.8); from 1.20.0, before 1.20.2 (fixed in 1.20.2)
Published 2025-08-06. Last modified 2026-06-17.