
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-6004 is a user lockout bypass vulnerability in HashiCorp Vault and Vault Enterprise affecting the Userpass and LDAP authentication methods. The flaw allows unauthenticated attackers to circumvent the account lockout mechanism designed to prevent repeated failed authentication attempts. It affects Vault Community Edition and Enterprise versions from 1.13.0 up to (but not including) 1.20.1, with specific Enterprise patch branches at 1.19.7, 1.18.12, and 1.16.23. Disclosed on August 1, 2025, it carries a CVSS v3.1 base score of 5.3 (Medium) (GitHub Advisory, HashiCorp Advisory).
The vulnerability is classified as CWE-307 (Improper Restriction of Excessive Authentication Attempts), meaning Vault fails to properly enforce its user lockout policy for the Userpass and LDAP auth methods (GitHub Advisory). An unauthenticated remote attacker can exploit this by sending repeated authentication requests over the network without triggering the lockout threshold, effectively bypassing the brute-force protection control. No special privileges or user interaction are required, and attack complexity is low. A technical write-up by the discovering researchers is available at Cyata AI's blog (Cyata AI Blog).
Successful exploitation allows attackers to conduct unlimited authentication attempts against Vault's Userpass and LDAP auth methods without being locked out, significantly increasing the risk of credential compromise through brute-force, password spraying, or credential stuffing attacks. While the vulnerability itself does not directly expose secrets or grant access, it undermines a key defense-in-depth control, and if credentials are guessed successfully, an attacker could gain unauthorized access to Vault-managed secrets, tokens, and sensitive infrastructure credentials. The integrity impact is rated Low (no confidentiality or availability impact from the bypass alone), but the downstream risk to secrets stored in Vault is considerably higher (GitHub Advisory, HashiCorp Advisory).
There is no public proof-of-concept exploit code and no confirmed in-the-wild exploitation as of the time of disclosure (GitHub Advisory). The EPSS score is approximately 0.039–0.115%, placing it in the lower percentiles for near-term exploitation likelihood. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the attack pattern aligns with well-known techniques including password spraying (CAPEC-565), credential stuffing (CAPEC-600), and brute-force (CAPEC-49), making it a viable enabler for credential-based attacks against exposed Vault instances (Cyata AI Blog).
GET /v1/sys/auth).POST /v1/auth/userpass/login/<username> with varying passwords) without triggering account lockout, leveraging the bypass to conduct password spraying or brute-force attacks at scale.GET /v1/secret/data/<path>), potentially accessing database credentials, API keys, or cloud provider credentials stored in Vault (HashiCorp Advisory, Cyata AI Blog).POST /v1/auth/userpass/login/<username> or POST /v1/auth/ldap/login/<username> from a single or rotating set of source IPs without triggering lockout responses.HashiCorp has released patches addressing this vulnerability: upgrade to Vault Community Edition 1.20.1 or Vault Enterprise 1.20.1, 1.19.7, 1.18.12, or 1.16.23 as appropriate for your release track (HashiCorp Advisory, GitHub Advisory). As interim mitigations, organizations should implement multi-factor authentication where possible, restrict network access to Vault's API to trusted networks only, and closely monitor authentication logs for anomalous login patterns. After patching, verify that the user lockout mechanism is functioning correctly by reviewing Vault's auth configuration.
The vulnerability was discovered and reported by researchers at Cyata AI, who published a blog post describing zero-day flaws found in HashiCorp Vault's authentication, identity, and authorization systems (Cyata AI Blog). Security news outlets including CyberSecurityNews, GBHackers, and CyberPress covered the disclosure, with some headlines emphasizing "zero-day" and "remote code execution" framing — though CVE-2025-6004 specifically concerns lockout bypass rather than RCE (CyberSecurityNews). Community discussion on social media (Twitter/X via RedPacketSecurity) noted the advisory shortly after publication. A technical TL;DR post was also published at 0dave.ch providing a concise breakdown of the vulnerability (0dave.ch).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."