DirectorySecurity AdvisoriesPricing
/
Sign in
Security Advisories

CVE-2025-11621

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2025-11621

Severity

8.1

High

CVSS V3

Description

Vault and Vault Enterprise’s (“Vault”) AWS Auth method may be susceptible to authentication bypass if the role of the configured bound_principal_iam is the same across AWS accounts, or uses a wildcard. This vulnerability, CVE-2025-11621, is fixed in Vault Community Edition 1.21.0 and Vault Enterprise 1.21.0, 1.20.5, 1.19.11, and 1.16.27

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-11621

Affected packages


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing