Database/Control plane, storage & DevOps
HashiCorp Vault: Operator with write on the root namespace identity endpoint escalates self/others to the root policy
CVSS 7.2CVE-2024-9180Control plane, storage & DevOpscurated
Impact
Operator with write on the root namespace identity endpoint escalates self/others to the root policy
Who can reach it
Network (remote)
What to do
Control-plane: upgrade; re-scope operator policies
References
Related entries
- HashiCorp Vault: KV v2 leaks sensitive payload content into server and audit logs on malformed requestsCVE-2025-4166 · HashiCorp VaultMedium
- HashiCorp Vault: Root-namespace operator with write on sys/audit gains code execution on the Vault hostCVE-2025-6000 · HashiCorp VaultCritical
- HashiCorp Vault: GCP secrets engine drops existing IAM Conditions when creating/updating rolesetsCVE-2023-5077 · HashiCorp VaultHigh
- Palo Alto PAN-OS: Admin with mgmt-interface access performs firewall actions as rootCVE-2024-9474 · Palo Alto PAN-OSHigh
- Volcano (scheduler, Elastic service and extender plugin response handling): The scheduler reads unbounded responsesCVE-2025-32777 · Volcano (scheduler, Elastic service and extender plugin response handling)High
- Oracle ZFS Storage Appliance Kit: HTTP-reachable flaw in Block Storage allows full appliance takeoverCVE-2025-62290 · Oracle ZFS Storage Appliance Kit 8.8 (Block Storage component)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.