Database/Control plane, storage & DevOps
HashiCorp Vault: Root-namespace operator with write on sys/audit gains code execution on the Vault host
CVSS 9.1CVE-2025-6000Control plane, storage & DevOpscurated
Impact
Root-namespace operator with write on sys/audit gains code execution on the Vault host via the plugin directory
Who can reach it
Network (remote)
What to do
Control-plane: URGENT - Vault holds tenant and BMC creds; upgrade + rotate root token
References
Related entries
- HashiCorp Vault: GCP secrets engine drops existing IAM Conditions when creating/updating rolesetsCVE-2023-5077 · HashiCorp VaultHigh
- HashiCorp Vault: Operator with write on the root namespace identity endpoint escalates self/others to the root policyCVE-2024-9180 · HashiCorp VaultHigh
- HashiCorp Vault: KV v2 leaks sensitive payload content into server and audit logs on malformed requestsCVE-2025-4166 · HashiCorp VaultMedium
- Lantronix EDS3000PS serial-to-Ethernet device server: Full bypass of the management-page loginCVE-2025-67039 · Lantronix EDS3000PS serial-to-Ethernet device serverCritical
- Palo Alto PAN-OS: GlobalProtect portal/gateway auth bypassCVE-2026-0257 · Palo Alto PAN-OSCritical
- Grafana MCP Server: caller-controlled X-Grafana-URL header turns grafana_api_request into a full SSRF primitiveCVE-2026-19516 · mcp-grafana (Grafana MCP Server, X-Grafana-URL destination control)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.