Description

Vault and Vault Enterprise’s (“Vault”) AWS Auth method may be susceptible to authentication bypass if the role of the configured bound_principal_iam is the same across AWS accounts, or uses a wildcard. This vulnerability, CVE-2025-11621, is fixed in Vault Community Edition 1.21.0 and Vault Enterprise 1.21.0, 1.20.5, 1.19.11, and 1.16.27

INFO

Published Date :

2025-10-23T19:08:54.989Z

Last Modified :

2026-02-26T16:57:11.235Z

Source :

HashiCorp
AFFECTED PRODUCTS

The following products are affected by CVE-2025-11621 vulnerability.

Vendors Products
Hashicorp
  • Vault
  • Vault Enterprise

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact