CVE-2022-40186
HashiCorp Vault vulnerability analysis and mitigation

Overview

A vulnerability was discovered in HashiCorp Vault and Vault Enterprise (CVE-2022-40186) affecting versions 1.8.0 through 1.11.2. The vulnerability was identified by the Vault engineering team and disclosed on September 20, 2022. The issue affects the Identity Engine component where entity aliases mapped to a single entity share the same alias name but have different mount accessors (HashiCorp Discussion).

Technical details

The vulnerability occurs when entity aliases mapped to a single entity share the same alias name but have different mount accessors, causing Vault to leak metadata between the aliases. Within a single entity, the metadata of an entity alias of an auth method may be overwritten when executing a login operation for an auth method with the same alias name. This vulnerability has received a CVSS score of 9.1 (CRITICAL) with a vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N (NetApp Security).

Impact

The metadata leak may result in unexpected access if templated policies are using alias metadata for path names. When ACL policies are deployed, the identity.entity.aliases..name key may be overwritten for a different mount accessor with the same alias name, potentially granting access for the first auth method to access the second auth method's mount accessor. This could lead to unintended access of data (HashiCorp Discussion).

Mitigation and workarounds

The vulnerability has been fixed in Vault versions 1.11.3, 1.10.6, and 1.9.9. Organizations should evaluate the risk and consider upgrading to these or newer versions. It is recommended to review existing authentication methods to ensure proper functionality and operation, particularly in cases where custom entity aliases have been explicitly set in Vault configuration and duplicate alias names may exist. Additionally, organizations should consider using Vault's feature to auto-generate entity alias names to ensure duplicates are not created in the future (HashiCorp Discussion).

Additional resources


SourceThis report was generated using AI

Related HashiCorp Vault vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-61729HIGH7.5
  • cAdvisorcAdvisor
  • crane-fips
NoYesDec 02, 2025
CVE-2025-63811HIGH7.5
  • HashiCorp VaultHashiCorp Vault
  • vault-fips-1.19
NoYesNov 12, 2025
CVE-2025-61727MEDIUM6.5
  • cAdvisorcAdvisor
  • prometheus-redis-exporter-fips
NoYesDec 03, 2025
CVE-2025-58181MEDIUM5.3
  • cAdvisorcAdvisor
  • actions-runner-controller
NoYesNov 19, 2025
CVE-2025-47914MEDIUM5.3
  • cAdvisorcAdvisor
  • falcosidekick-fips
NoYesNov 19, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management