CVE-2025-6010
HashiCorp Vault vulnerability analysis and mitigation

Overview

CVE-2025-6010 is a rejected CVE entry that was withdrawn by its CVE Numbering Authority (CNA). The CVE was initially associated with a potential user enumeration vulnerability in HashiCorp Vault's userpass authentication method, but has since been officially rejected. No CVSS score or severity rating is applicable to a rejected CVE (CVE Project).

Technical details

Because CVE-2025-6010 has been officially rejected by its CNA, no authoritative technical details are available for this identifier. The CVE was briefly associated with research into HashiCorp Vault authentication flaws, specifically around user enumeration in the userpass auth method, but the rejection indicates the issue was either a duplicate, out of scope, or otherwise not meeting CVE criteria (HashiCorp Discuss, Cyata AI Blog).

Exploitability

CVE-2025-6010 has been rejected and carries no exploitability status. It is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, and no EPSS score is applicable. Any related HashiCorp Vault user enumeration concerns should be tracked under the separately issued advisory HCSEC-2025-21 (HashiCorp Discuss).

Mitigation and workarounds

Since CVE-2025-6010 is a rejected CVE, no patches or workarounds are tied to this identifier. Organizations concerned about HashiCorp Vault userpass authentication security should consult the official HashiCorp security advisory HCSEC-2025-21 for applicable guidance and patched versions (HashiCorp Discuss).

Community reactions

A blog post by Cyata AI discussed zero-day flaws in HashiCorp Vault authentication, identity, and authorization, which appears to have been the research context that initially prompted this CVE's creation before its rejection (Cyata AI Blog). No significant broader community or media reactions are associated with this rejected CVE identifier.

Additional resources


SourceThis report was generated using AI

Related HashiCorp Vault vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-84304HIGH8.7
  • cAdvisor logocAdvisor
  • envoy-gateway-fips-1.8
NoYesSep 01, 2026
CVE-2026-56854HIGH7.5
  • New Relic Agent logoNew Relic Agent
  • filebrowser-fips
NoYesAug 28, 2026
CVE-2026-5006MEDIUM6.8
  • HashiCorp Vault logoHashiCorp Vault
  • cpe:2.3:a:hashicorp:vault
NoYesAug 24, 2026
CVE-2026-84303MEDIUM6.3
  • New Relic Agent logoNew Relic Agent
  • kubescape-fips
NoYesSep 01, 2026
CVE-2026-45404MEDIUM5.9
  • HashiCorp Vault logoHashiCorp Vault
  • flipt-fips-2
NoYesAug 24, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management