CVE-2025-5999: CWE-266: Incorrect Privilege Assignment in HashiCorp Vault
CVE-2025-5999 is a privilege escalation vulnerability in HashiCorp Vault where a privileged operator with write access to the root namespace’s identity endpoint can escalate token privileges to the root policy. This vulnerability affects certain versions of Vault and has been fixed in multiple patched releases.
AI Analysis
Technical Summary
This vulnerability (CWE-266: Incorrect Privilege Assignment) allows a Vault operator who already has write permissions to the root namespace’s identity endpoint to escalate their own or another user's token privileges to Vault's root policy. This could lead to full administrative control within Vault. The issue has been addressed and fixed in Vault Community Edition 1.20.0 and Vault Enterprise versions 1.20.0, 1.19.6, 1.18.11, and 1.16.22.
Potential Impact
An attacker or operator with write access to the root namespace’s identity endpoint can escalate token privileges to the root policy, resulting in complete control over Vault. This includes the ability to read, write, and delete secrets and configurations, potentially compromising all stored sensitive data and system integrity.
Mitigation Recommendations
Apply the official patches provided by HashiCorp. Upgrade to Vault Community Edition 1.20.0 or Vault Enterprise 1.20.0, 1.19.6, 1.18.11, or 1.16.22 to remediate this vulnerability. No other mitigations are indicated by the vendor advisory.
CVE-2025-5999: CWE-266: Incorrect Privilege Assignment in HashiCorp Vault
Description
CVE-2025-5999 is a privilege escalation vulnerability in HashiCorp Vault where a privileged operator with write access to the root namespace’s identity endpoint can escalate token privileges to the root policy. This vulnerability affects certain versions of Vault and has been fixed in multiple patched releases.
CVSS v3.1
Score 7.2high
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CWE-266: Incorrect Privilege Assignment) allows a Vault operator who already has write permissions to the root namespace’s identity endpoint to escalate their own or another user's token privileges to Vault's root policy. This could lead to full administrative control within Vault. The issue has been addressed and fixed in Vault Community Edition 1.20.0 and Vault Enterprise versions 1.20.0, 1.19.6, 1.18.11, and 1.16.22.
Potential Impact
An attacker or operator with write access to the root namespace’s identity endpoint can escalate token privileges to the root policy, resulting in complete control over Vault. This includes the ability to read, write, and delete secrets and configurations, potentially compromising all stored sensitive data and system integrity.
Mitigation Recommendations
Apply the official patches provided by HashiCorp. Upgrade to Vault Community Edition 1.20.0 or Vault Enterprise 1.20.0, 1.19.6, 1.18.11, or 1.16.22 to remediate this vulnerability. No other mitigations are indicated by the vendor advisory.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- HashiCorp
- Date Reserved
- 2025-06-11T14:37:52.021Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 688cfdc0ad5a09ad00cae4c9
Added to database: 08/01/2025, 17:47:44 UTC
Last enriched: 09/08/2026, 13:08:33 UTC
Last updated: 09/10/2026, 19:36:51 UTC
Views: 179
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.