Researchers have found 14 bugs in various components of HashiCorp Vault and CyberArk Conjur, two open-source credential management vaults, allowing RCE attacks that could bypass authentication checks, gain access to secrets, impersonate identities, and execute arbitrary code.
See also: Exploiting RCE vulnerability in Trend Micro Apex One

In enterprise environments, non-human identities, such as those used by applications and machines, are estimated to outnumber human identities by a ratio of 150 to 1.This makes credential management systems, which often hold what can be considered the “keys to the kingdom,” a critical component of IT infrastructure.
Recognizing this, researchers from cybersecurity firm Cyata analyzed two widely used open source credential management solutions: HashiCorp Vault and CyberArk Conjur. Their findings, which include 14 vulnerabilities that allow chains of remote code execution (RCE) attacks in both products, were presented at the Black Hat USA security conference in Las Vegas.
HashiCorp Vault and CyberArk Conjur do more than just store credentials. They allow organizations to set policies for access and use of these secrets, offering access controls , automated secret rotation, auditing, and more. Designed to integrate with DevOps, these systems are often part of CI/CD pipelines.
See also: Hackers actively exploit critical RCE in WordPress Alone
The attack chains discovered by Cyata, which were responsibly disclosed to HashiCorp and CyberArk and have now been patched, stemmed from vulnerabilities in authentication, validation, and policy enforcement mechanisms. These vulnerabilities allowed lock bypasses, policy check evasion, and account impersonation.

Cyata's attack chain against CyberArk Conjur began with a simple flaw in the code used to validate AWS IAM. Conjur supports authentication for AWS instances via AWS's Security Token Service (STS), allowing workflows to authenticate without hard-coded credentials.
To identify itself, an AWS instance creates a signed header, which Conjur forwards to AWS STS. STS validates the signature and returns the instance's identity. However, STS servers are specific to each region. For example, instances in us-east-1 should use sts.us-east-1.amazonaws.com , and Conjur determines the correct STS region based on the hostname included in the signed header.
The problem is that the computer name in the header can be inspected by the attacker. And while this would not be a problem because a fake signature would normally fail validation from a legitimate STS case, the Conjur code failed to sanitize special characters like ‘;’ in the computer name.
See also: CISA warns of PaperCut RCE vulnerability exploitation
This allowed the researchers to create a request with a hostname like sts.cyata.ai?, which the Conjur code converted to sts.cyata.ai?.amazonaws.com, adding the correct domain. However, in practice, the part after the added question mark is ignored in URLs, so the requests are sent to sts.cyata.ai, a malicious STS server under the researchers' control, passing validation.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
