Incorrect Privilege Assignment
CVE-2025-5999
Summary
A privileged Vault operator with write permissions to the root namespaces identity endpoint could escalate their own or another users token privileges to Vaults root policy. This issue affects Vault Community Edition versions 0.10.4 prior to 1.20.0 and is fixed in Vault Enterprise 1.20.0, 1.19.6, 1.18.11, and 1.16.22.
- LOW
- NETWORK
- HIGH
- UNCHANGED
- NONE
- HIGH
- HIGH
- HIGH
CWE-266 - Incorrect Privilege Assignment
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
References
Advisory Timeline
- Published