CVE-2025-11621 | HashiCorp Vault/Vault Enterprise up to 1.20.x AWS Auth Method authentication bypass (EUVD-2025-35715)
A vulnerability, which was classified as critical, has been found in HashiCorp Vault and Vault Enterprise up to 1.20.x. This impacts an unknown function of the component AWS Auth Method. This manipulation causes authentication bypass using alternate channel.
This vulnerability is handled as CVE-2025-11621. The attack can be initiated remotely. There is not any exploit available.
It is advisable to upgrade the affected component.