Vault

Vendor:

First CVE: Dec 5, 2018 · Active for 7 years

72
Total CVEs
More Total CVEs than 99% of tracked products
9.0
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 42% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Vault over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 5, 2018
7 years ago
Most Recent CVE
Apr 17, 2026
101 days ago

CVE Severity & Scoring

Vault72 CVEs
All CVEs352,785 CVEs
LowMediumHighCritical
Attack Vector
Local5 (6.9%)
Network66 (91.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (1.4%)
Attack Complexity
Low63 (87.5%)
High9 (12.5%)
Unknown0 (0.0%)
User Interaction
None66 (91.7%)
Unknown0 (0.0%)
Required6 (8.3%)
Privileges Required
Low21 (29.2%)
High11 (15.3%)
None40 (55.6%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (72 CVEs).

72 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A privileged Vault operator within the root namespace with write permission to {{sys/audit}} may obtain code execution on the underlying host if a plugin directory is set in Vault’
Aug 1, 20259.134NONO
If a Vault auth mount is configured to pass through the "Authorization" header, and the "Authorization" header is used to authenticate to Vault, Vault forwarded the Vault token to
Apr 17, 20268.831NONO
Vault and Vault Enterprise (“Vault”) TLS certificate auth method did not correctly validate client certificates when configured with a non-CA certificate as trusted certificate. In
Mar 4, 20249.830NONO
Vault is vulnerable to a denial-of-service condition where an unauthenticated attacker can repeatedly initiate or cancel root token generation or rekey operations, occupying the si
Apr 17, 20267.529NONO
An authenticated user with access to a kvv2 path through a policy containing a glob may be able to delete secrets they were not authorized to read or write, resulting in denial-of-
Apr 17, 20268.129NONO
Vault and Vault Enterprise’s (“Vault”) AWS Auth method may be susceptible to authentication bypass if the role of the configured bound_principal_iam is the same across AWS accounts
Oct 23, 20258.129NONO
An issue was discovered in HashiCorp Vault and Vault Enterprise before 1.11.3. A vulnerability in the Identity Engine was found where, in a deployment where an entity has multiple
Sep 22, 20229.129NONO
The official vault docker images before 0.11.6 contain a blank password for a root user. System using the vault docker container deployed by affected versions of the docker image m
Dec 17, 20209.829NONO
Vault’s PKI engine’s ACME validation did not reject local targets when issuing http-01 and tls-alpn-01 challenges. This may lead to these requests being sent to local network targe
Apr 17, 20268.628NONO
Vault and Vault Enterprise (“Vault”) are vulnerable to an unauthenticated denial of service when processing JSON payloads. This occurs due to a regression from a previous fix for [
Oct 23, 20257.528NONO

Exploit Exposure

Signals from CVEs in this product scope (72 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (72 CVEs).

Media Mentions

Signals from CVEs in this product scope (72 CVEs).

Top CNAs Publishing CVEs For Vault

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.9.014.91.4%00
1.8.416.51.0%00
1.6.117.51.3%00
1.6.017.51.3%00
1.20.066.20.4%00
1.19.018.80.4%00
1.18.017.50.5%00
1.14.025.20.6%00
1.13.414.90.6%00
1.12.814.90.6%00
1.11.019.11.5%00