HomeSecurityVulnerability in HashiCorp Vault allows access to the system without valid credentials

Vulnerability in HashiCorp Vault allows access to the system without valid credentials

A critical vulnerability has been identified in the HashiCorp Vault Terraform Provider, which could allow attackers to bypass the authentication mechanism and gain access to Vault without valid credentials.

See also: Vulnerabilities in Tenda devices allow code execution

HashiCorp Vault

The vulnerability, identified as CVE-2025-13357, affects organizations using LDAP authentication in Vault. The issue stems from an incorrect default setting in the Terraform Provider; specifically, the deny_null_bind was set to false by default for the LDAP authentication method. This setting created a serious security hole because the LDAP server allowed unauthenticated connections.

If exploited, the vulnerability allows malicious users to log in to Vault without providing valid credentials.

Authentication bypass is a significant threat to organizations that store sensitive secrets, encryption keys, and other critical data in Vault. HashiCorp has released updates that address the issue. The following are recommended:

See also: CISA: Oracle Identity Manager vulnerability in the KEV Catalog

Vulnerability in HashiCorp Vault allows access to the system without valid credentials
  • Upgrade to Vault Terraform Provider v5.5.0, which correctly sets the deny_null_bind=true by default.
  • Upgrade to Vault Community Edition 1.21.1 or Vault Enterprise 1.21.1, 1.20.6, 1.19.12 or 1.16.28.
  • Make sure that the deny_null_bind is explicitly set to true in all LDAP authentication settings.

Organizations using older versions of the provider should explicitly set the parameter in their Terraform files and apply the changes immediately. Fixed versions of Vault no longer accept empty password values, thus preventing unauthenticated LDAP connections via this authentication method.

HashiCorp announced that this deprecated parameter will be removed in future releases. The vulnerability was discovered by an independent researcher, who responsibly disclosed it to HashiCorp.

See also: Wireshark vulnerabilities allow system crash

Vulnerability in HashiCorp Vault allows access to the system without valid credentials

Organizations using Vault with LDAP authentication should prioritize applying these security updates to protect their infrastructure from potential exploitation.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS