Vault and Vault Enterprise's ("Vault") AWS Auth method may be susceptible to authentication bypass if the role of the configured boundprincipaliam is the same across AWS accounts, or uses a wildcard. This vulnerability is fixed in Vault Community Edition 1.21.0 and Vault Enterprise 1.21.0, 1.20.5, 1.19.11, and 1.16.27.
{
"nvd_published_at": "2025-10-23T19:15:48Z",
"cwe_ids": [
"CWE-288"
],
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2025-10-23T22:21:01Z"
}