CVE-2025-11621 - Vault AWS auth method bypass due to AWS client cache
CVE ID : CVE-2025-11621
Published : Oct. 23, 2025, 7:15 p.m. | 1 hour, 59 minutes ago
Description : Vault and Vault Enterprise’s (“Vault”) AWS Auth method may be susceptible to authentication bypass if the role of the configured bound_principal_iam is the same across AWS accounts, or uses a wildcard. This vulnerability, CVE-2025-11621, is fixed in Vault Community Edition 1.21.0 and Vault Enterprise 1.21.0, 1.20.5, 1.19.11, and 1.16.27
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Oct. 23, 2025, 7:15 p.m. | 1 hour, 59 minutes ago
Description : Vault and Vault Enterprise’s (“Vault”) AWS Auth method may be susceptible to authentication bypass if the role of the configured bound_principal_iam is the same across AWS accounts, or uses a wildcard. This vulnerability, CVE-2025-11621, is fixed in Vault Community Edition 1.21.0 and Vault Enterprise 1.21.0, 1.20.5, 1.19.11, and 1.16.27
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...