CVE-2025-6015
HashiCorp Vault vulnerability analysis and mitigation

Overview

CVE-2025-6015 is a login MFA rate limit bypass vulnerability in HashiCorp Vault and Vault Enterprise that allows attackers to bypass Multi-Factor Authentication rate limits and reuse Time-based One-Time Password (TOTP) tokens. It affects Vault Community Edition versions 1.10.0 through 1.20.0 and multiple Vault Enterprise version ranges. The vulnerability was published on August 1, 2025, with patches released simultaneously. It carries a CVSS v3.1 base score of 5.7 (Medium) (GitHub Advisory, HashiCorp Advisory).

Technical details

The root cause is classified as CWE-307 (Improper Restriction of Excessive Authentication Attempts), meaning Vault's login MFA subsystem fails to adequately enforce rate limits on authentication attempts. This allows a low-privileged attacker, with some user interaction required, to make repeated MFA validation requests over the network without being throttled, and to reuse previously issued TOTP tokens that should be invalidated after a single use. The attack vector is network-based with low attack complexity, requiring only low-level privileges (GitHub Advisory, HashiCorp Advisory).

Impact

Successful exploitation allows an attacker with low-privileged access to circumvent MFA protections on Vault login, potentially gaining unauthorized access to secrets, credentials, and other sensitive data stored in Vault. The CVSS scoring reflects a high confidentiality impact with no integrity or availability impact, meaning the primary risk is unauthorized read access to protected information. Given Vault's role as a secrets management platform, unauthorized access could expose API keys, database credentials, certificates, and other high-value secrets that could enable lateral movement across an organization's infrastructure (GitHub Advisory, HashiCorp Advisory).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The EPSS score is approximately 0.028% (0.000280), placing it in a low probability tier for near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.

Exploitation steps

  1. Reconnaissance: Identify internet-facing or internally accessible HashiCorp Vault instances running versions 1.10.0–1.20.0 (Community) or affected Enterprise versions using network scanning tools or service discovery.
  2. Obtain low-privileged credentials: Acquire or already possess a low-privileged Vault account (e.g., via credential stuffing, phishing, or insider access) that is subject to MFA enforcement at login.
  3. Initiate MFA login flow: Begin the Vault login process with the compromised credentials, triggering the MFA challenge (TOTP prompt).
  4. Bypass rate limiting: Submit repeated MFA validation requests without being throttled, exploiting the improper rate limit enforcement to make excessive authentication attempts.
  5. Reuse TOTP tokens: Replay a previously observed or intercepted TOTP token that should have been invalidated after first use, bypassing the one-time-use protection.
  6. Gain unauthorized access: Successfully authenticate to Vault, gaining access to secrets, policies, and other resources permitted by the compromised account's privileges (GitHub Advisory, HashiCorp Advisory).

Indicators of compromise

  • Logs: Vault audit logs showing an unusually high number of MFA validation attempts from a single user or IP address within a short time window; repeated login attempts with the same TOTP token value across multiple requests.
  • Network: Abnormal volume of POST requests to Vault's login MFA endpoints (e.g., /v1/auth/*/login or /v1/sys/mfa/validate) from a single source IP.
  • Behavioral: Successful Vault authentication events preceded by a large number of failed or repeated MFA attempts; authentication events at unusual hours or from unexpected geographic locations for a given user account.

Mitigation and workarounds

HashiCorp has released patched versions that should be applied immediately: Vault Community Edition 1.20.1, and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23 (GitHub Advisory, HashiCorp Advisory). As interim measures, administrators should review and audit recent authentication logs for suspicious MFA activity, implement additional rate-limiting at the network or load balancer level, and enforce strict access controls to limit the blast radius of any compromised accounts. Monitoring for anomalous login patterns is also recommended until patching is complete.

Community reactions

The vulnerability was disclosed by HashiCorp via their security advisory forum (HCSEC-2025-19) on August 1, 2025, with patches released simultaneously, indicating a coordinated disclosure process (HashiCorp Advisory). The advisory was picked up by standard vulnerability tracking services including Vulners, CVEFeed, and security aggregators shortly after publication. No notable independent researcher commentary or significant social media discussion beyond routine CVE tracking has been observed.

Additional resources


SourceThis report was generated using AI

Related HashiCorp Vault vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-56852HIGH7.5
  • cAdvisor logocAdvisor
  • hubble
NoYesJul 21, 2026
CVE-2026-46600HIGH7.5
  • cAdvisor logocAdvisor
  • ceph-csi-fips
NoYesJul 21, 2026
CVE-2026-42505MEDIUM5.3
  • Go logoGo
  • nri-cassandra-fips
NoYesJul 08, 2026
CVE-2026-14886NONEN/A
  • HashiCorp Vault logoHashiCorp Vault
  • cpe:2.3:a:hashicorp:vault
NoYesAug 10, 2026
CVE-2026-12624NONEN/A
  • HashiCorp Vault logoHashiCorp Vault
  • cpe:2.3:a:hashicorp:vault
NoYesAug 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management