Vault and Vault Enterprise’s (“Vault”) AWS Auth method may be susceptible to authentication bypass if the role of the configured bound_principal_iam is the same across AWS accounts, or uses a wildcard. This vulnerability, CVE-2025-11621, is fixed in Vault Community Edition 1.21.0 and Vault Enterprise 1.21.0, 1.20.5, 1.19.11, and 1.16.27
https://github.com/Nikhil-Ladha/cve-smasher-claude-plugin
https://github.com/advisories/GHSA-9g4h-h484-3578
Published: 2025-10-23
Updated: 2025-12-29
Named Vulnerability: GO-2025-4070Named Vulnerability: GHSA-9g4h-h484-3578
Base Score: 8.5
Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:N
Severity: High
Base Score: 8.1
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Severity: High
EPSS: 0.00489