
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-6010 is a rejected CVE entry that was withdrawn by its CVE Numbering Authority (CNA). The CVE was initially associated with a potential user enumeration vulnerability in HashiCorp Vault's userpass authentication method, but has since been officially rejected. No CVSS score or severity rating is applicable to a rejected CVE (CVE Project).
Because CVE-2025-6010 has been officially rejected by its CNA, no authoritative technical details are available for this identifier. The CVE was briefly associated with research into HashiCorp Vault authentication flaws, specifically around user enumeration in the userpass auth method, but the rejection indicates the issue was either a duplicate, out of scope, or otherwise not meeting CVE criteria (HashiCorp Discuss, Cyata AI Blog).
CVE-2025-6010 has been rejected and carries no exploitability status. It is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, and no EPSS score is applicable. Any related HashiCorp Vault user enumeration concerns should be tracked under the separately issued advisory HCSEC-2025-21 (HashiCorp Discuss).
Since CVE-2025-6010 is a rejected CVE, no patches or workarounds are tied to this identifier. Organizations concerned about HashiCorp Vault userpass authentication security should consult the official HashiCorp security advisory HCSEC-2025-21 for applicable guidance and patched versions (HashiCorp Discuss).
A blog post by Cyata AI discussed zero-day flaws in HashiCorp Vault authentication, identity, and authorization, which appears to have been the research context that initially prompted this CVE's creation before its rejection (Cyata AI Blog). No significant broader community or media reactions are associated with this rejected CVE identifier.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."