CVE-2025-5999 PUBLISHED

A privileged Vault operator with write permissions to the root namespace’s identity endpoint could escalate their own or another user’s token privileges to Vault’s root policy. Fixed in Vault Community Edition 1.20.0 and Vault Enterprise 1.20.0, 1.19.6, 1.18.11 and 1.16.22.

EPSS 0.03% · 8.2th percentile

Risk Scores

EPSS Score
0.03%
8.2th percentile

Affected Products

VendorProductVersions
Bitnamivault0.10.4
Bitnamivault0.10.4

Timeline

References

Open in Interactive Console →