A privileged Vault operator with write permissions to the root namespace’s identity endpoint could escalate their own or another user’s token privileges to Vault’s root policy. Fixed in Vault Community Edition 1.20.0 and Vault Enterprise 1.20.0, 1.19.6, 1.18.11 and 1.16.22.
Metrics
Affected Vendors & Products
References
History
Mon, 04 Aug 2025 12:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
threat_severity
|
threat_severity
|
Mon, 04 Aug 2025 09:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Hashicorp
Hashicorp vault |
|
Vendors & Products |
Hashicorp
Hashicorp vault |
Fri, 01 Aug 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 01 Aug 2025 18:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A privileged Vault operator with write permissions to the root namespace’s identity endpoint could escalate their own or another user’s token privileges to Vault’s root policy. Fixed in Vault Community Edition 1.20.0 and Vault Enterprise 1.20.0, 1.19.6, 1.18.11 and 1.16.22. | |
Title | Vault Root Namespace Operator May Elevate Token Privileges | |
Weaknesses | CWE-266 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: HashiCorp
Published: 2025-08-01T17:38:58.409Z
Updated: 2025-08-01T18:08:59.605Z
Reserved: 2025-06-11T14:37:52.021Z
Link: CVE-2025-5999

Updated: 2025-08-01T18:08:52.857Z

Status : Awaiting Analysis
Published: 2025-08-01T18:15:56.257
Modified: 2025-08-04T15:06:15.833
Link: CVE-2025-5999
