Vault
Vendor:
First CVE: Dec 5, 2018 · Active for 7 years
72
Total CVEs
More Total CVEs than 99% of tracked products
9.0
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 42% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Vault over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 5, 2018
7 years ago
Most Recent CVE
Apr 17, 2026
101 days ago
CVE Severity & Scoring
Vault72 CVEs
46%
40%
10%
All CVEs352,785 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local5 (6.9%)
Network66 (91.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (1.4%)
Attack Complexity
Low63 (87.5%)
High9 (12.5%)
Unknown0 (0.0%)
User Interaction
None66 (91.7%)
Unknown0 (0.0%)
Required6 (8.3%)
Privileges Required
Low21 (29.2%)
High11 (15.3%)
None40 (55.6%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (72 CVEs).
72 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-6000CRITICAL A privileged Vault operator within the root namespace with write permission to {{sys/audit}} may obtain code execution on the underlying host if a plugin directory is set in Vault’ | Aug 1, 2025 | 9.1 | 34 | NO | NO |
CVE-2026-4525HIGH If a Vault auth mount is configured to pass through the "Authorization" header, and the "Authorization" header is used to authenticate to Vault, Vault forwarded the Vault token to | Apr 17, 2026 | 8.8 | 31 | NO | NO |
CVE-2024-2048CRITICAL Vault and Vault Enterprise (“Vault”) TLS certificate auth method did not correctly validate client certificates when configured with a non-CA certificate as trusted certificate. In | Mar 4, 2024 | 9.8 | 30 | NO | NO |
CVE-2026-5807HIGH Vault is vulnerable to a denial-of-service condition where an unauthenticated attacker can repeatedly initiate or cancel root token generation or rekey operations, occupying the si | Apr 17, 2026 | 7.5 | 29 | NO | NO |
CVE-2026-3605HIGH An authenticated user with access to a kvv2 path through a policy containing a glob may be able to delete secrets they were not authorized to read or write, resulting in denial-of- | Apr 17, 2026 | 8.1 | 29 | NO | NO |
CVE-2025-11621HIGH Vault and Vault Enterprise’s (“Vault”) AWS Auth method may be susceptible to authentication bypass if the role of the configured bound_principal_iam is the same across AWS accounts | Oct 23, 2025 | 8.1 | 29 | NO | NO |
CVE-2022-40186CRITICAL An issue was discovered in HashiCorp Vault and Vault Enterprise before 1.11.3. A vulnerability in the Identity Engine was found where, in a deployment where an entity has multiple | Sep 22, 2022 | 9.1 | 29 | NO | NO |
CVE-2020-35192CRITICAL The official vault docker images before 0.11.6 contain a blank password for a root user. System using the vault docker container deployed by affected versions of the docker image m | Dec 17, 2020 | 9.8 | 29 | NO | NO |
CVE-2026-5052HIGH Vault’s PKI engine’s ACME validation did not reject local targets when issuing http-01 and tls-alpn-01 challenges. This may lead to these requests being sent to local network targe | Apr 17, 2026 | 8.6 | 28 | NO | NO |
CVE-2025-12044HIGH Vault and Vault Enterprise (“Vault”) are vulnerable to an unauthenticated denial of service when processing JSON payloads. This occurs due to a regression from a previous fix for [ | Oct 23, 2025 | 7.5 | 28 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (72 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (72 CVEs).
Media Mentions
Signals from CVEs in this product scope (72 CVEs).
Top CNAs Publishing CVEs For Vault
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.9.0 | 1 | 4.9 | 1.4% | 0 | 0 |
| 1.8.4 | 1 | 6.5 | 1.0% | 0 | 0 |
| 1.6.1 | 1 | 7.5 | 1.3% | 0 | 0 |
| 1.6.0 | 1 | 7.5 | 1.3% | 0 | 0 |
| 1.20.0 | 6 | 6.2 | 0.4% | 0 | 0 |
| 1.19.0 | 1 | 8.8 | 0.4% | 0 | 0 |
| 1.18.0 | 1 | 7.5 | 0.5% | 0 | 0 |
| 1.14.0 | 2 | 5.2 | 0.6% | 0 | 0 |
| 1.13.4 | 1 | 4.9 | 0.6% | 0 | 0 |
| 1.12.8 | 1 | 4.9 | 0.6% | 0 | 0 |
| 1.11.0 | 1 | 9.1 | 1.5% | 0 | 0 |