V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2026-4525
ANC
High

If a Vault auth mount is configured to pass through the "Authorization" header, and the "Authorization" header is used to authenticate to V…

CVSS
8.8
High
EPSS
0.00
p22
Published
2026-01-01
Updated
2026-01-01
Description

If a Vault auth mount is configured to pass through the "Authorization" header, and the "Authorization" header is used to authenticate to Vault, Vault forwarded the Vault token to the auth plugin backend. Fixed in 2.0.0, 1.21.5, 1.20.10, and 1.19.16.

Tags · CWE
CWE-201
CAPEC-12
CAPEC-217
CAPEC-612
CAPEC-613
CAPEC-618
CAPEC-619
CAPEC-621
CAPEC-622
CAPEC-623
Affected products
Vault 0.11.2–1.19.16Vault 0.11.2–2.0.0Vault 1.20.0–1.20.10Vault 1.21.0–1.21.5
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Timeline
2026-01-01
Published
2026-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: L
Low (L)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.003 · p22
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
Tracked
Tracked
vault*Tracked