Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
HashiCorp Vault Vulnerability Allow Attackers to Authenticate to Vault Without Valid Credentials

HashiCorp Vault Vulnerability Allow Attackers to Authenticate to Vault Without Valid Credentials

Posted on November 25, 2025November 25, 2025 By CWS

A crucial safety flaw has been found in HashiCorp’s Vault Terraform Supplier that would enable attackers to bypass authentication and entry Vault with out legitimate credentials.

The vulnerability, tracked as CVE-2025-13357, impacts organizations utilizing LDAP authentication with Vault. The safety situation stems from an incorrect default configuration in Vault’s Terraform Supplier.

Particularly, the supplier set the deny_null_bind parameter to false by default for the LDAP authentication technique.

HashiCorp Vault Vulnerability

This misconfiguration created a harmful safety hole as a result of the underlying LDAP server permitted unauthenticated connections.

When exploited, this vulnerability permits menace actors to authenticate to Vault with out offering legit credentials.

This authentication bypass poses vital dangers to organizations storing delicate secrets and techniques, encryption keys, and different crucial knowledge in Vault.

CVE IDAffected ProductsAffected VersionsImpactCVE-2025-13357Vault Terraform Providerv4.2.0 to v5.4.0Authentication Bypass

HashiCorp has launched fixes addressing this vulnerability. Organizations ought to take the next actions:

Replace to Vault Terraform Supplier v5.5.0, which accurately units the deny_null_bind parameter to true by default.

Moreover, improve to Vault Neighborhood Version 1.21.1 or Vault Enterprise variations 1.21.1, 1.20.6, 1.19.12, or 1.16.28.

Make sure the deny_null_bind parameter is explicitly set to true in LDAP auth technique configurations.

Organizations utilizing older supplier variations ought to explicitly set the parameter of their Terraform recordsdata and apply the modifications instantly.

The patched Vault variations not settle for empty password strings, successfully stopping unauthenticated LDAP connections through the authentication technique.

HashiCorp has introduced that this outdated parameter shall be eliminated in future releases. This vulnerability was recognized by a third-party researcher who responsibly disclosed it to HashiCorp.

Organizations utilizing Vault with LDAP authentication ought to prioritize making use of these safety updates to guard their infrastructure from potential exploitation.

Comply with us on Google Information, LinkedIn, and X for each day cybersecurity updates. Contact us to characteristic your tales.

Cyber Security News Tags:Attackers, Authenticate, Credentials, HashiCorp, Valid, Vault, Vulnerability

Post navigation

Previous Post: Microsoft’s Update Health Tools Configuration Vulnerability Let Attackers Execute Arbitrary Code Remotely
Next Post: Canon Allegedly Breached by Clop Ransomware via Oracle E-Business Suite 0-Day Hack

Related Posts

China-Linked Hackers Target Telecoms With New Malware China-Linked Hackers Target Telecoms With New Malware Cyber Security News
Threat actors Allegedly Claim Discord Dataset Containing 78,541,207 Files Threat actors Allegedly Claim Discord Dataset Containing 78,541,207 Files Cyber Security News
Essential Phishing Defense Strategies for CISOs Essential Phishing Defense Strategies for CISOs Cyber Security News
ZAP Enhances Security with OWASP PTK Add-On ZAP Enhances Security with OWASP PTK Add-On Cyber Security News
Firefox Releases Security Update to Fix Multiple Vulnerabilities Allowing Arbitrary Code Execution Firefox Releases Security Update to Fix Multiple Vulnerabilities Allowing Arbitrary Code Execution Cyber Security News
Speaker Proposal Deadline Approaches for OpenSSL Conference 2025 in Prague Speaker Proposal Deadline Approaches for OpenSSL Conference 2025 in Prague Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • WhatsApp Introduces Scam Alert to Enhance User Safety
  • Lazarus Exploits Windows Flaw to Deploy New Backdoor
  • AI-Powered Cyberattack Targets Taiwan Government
  • Ivanti EPM Update Resolves Critical Security Flaws
  • Adobe ColdFusion Flaws Pose Severe Security Risks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • WhatsApp Introduces Scam Alert to Enhance User Safety
  • Lazarus Exploits Windows Flaw to Deploy New Backdoor
  • AI-Powered Cyberattack Targets Taiwan Government
  • Ivanti EPM Update Resolves Critical Security Flaws
  • Adobe ColdFusion Flaws Pose Severe Security Risks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark