<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/security-researchers-uncover-zero-day-vulnerabilities-in-hashicorp-vault-peqvmxapd" -->

---
title: Security Researchers Uncover Zero-Day Vulnerabilities in...
description: Security researchers discovered 14 critical vulnerabilities in HashiCorp Vault and CyberArk Conjur, including authentication bypasses, MFA evasion, privilege...
canonical: https://daily.dev/posts/security-researchers-uncover-zero-day-vulnerabilities-in-hashicorp-vault-peqvmxapd
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Security Researchers Uncover Zero-Day Vulnerabilities in HashiCorp Vault | daily.dev
og:description: Security researchers discovered 14 critical vulnerabilities in HashiCorp Vault and CyberArk Conjur, including authentication bypasses, MFA evasion, privilege...
og:url: https://daily.dev/posts/security-researchers-uncover-zero-day-vulnerabilities-in-hashicorp-vault-peqvmxapd
og:image: https://api.daily.dev/og/posts/peqvMxapD.png
og:image:alt: Security Researchers Uncover Zero-Day Vulnerabilities in HashiCorp Vault
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Security Researchers Uncover Zero-Day Vulnerabilities in HashiCorp Vault

**[Collections](https://daily.dev/sources/collections)** · 2 min read · 1 upvotes · 0 comments

## Summary

Security researchers discovered 14 critical vulnerabilities in HashiCorp Vault and CyberArk Conjur, including authentication bypasses, MFA evasion, privilege escalation, and remote code execution. The flaws affected multiple authentication methods and represented the first public RCE exploit in Vault's 10-year history. Both vendors have released patches and security bulletins to address these issues.

## Content

Security researchers have uncovered a series of critical vulnerabilities in HashiCorp Vault and CyberArk Conjur, two widely used open-source secrets management systems. These discoveries, totaling 14 vulnerabilities, include serious exploits such as authentication bypasses, multi-factor authentication (MFA) evasion, privilege escalation, and remote code execution (RCE) attack chains.

The vulnerabilities emerged from logical errors within the core authentication flows and policy enforcement mechanisms of these systems. Specifically, the issues impacted multiple authentication methods in HashiCorp Vault, such as userpass, LDAP, TOTP MFA, and certificate-based systems, some of which have been present for nearly a decade. These logic flaws allow attackers to bypass authentication processes, impersonate users, escalate privileges, and potentially achieve full system compromise through plugin interface abuse.

Notably, this was the first public disclosure of an RCE exploit in HashiCorp Vault's 10-year history. The flaws enabled attackers to access stored credentials and execute remote code, which could have devastating consequences for organizations relying on these systems to safeguard their sensitive data.

Both HashiCorp and CyberArk have responded promptly to these findings by releasing patches to address the vulnerabilities. Detailed security bulletins have been published by both vendors, providing information on the fixes and reinforcing the need for robust, continually evolving security measures within critical infrastructure protection.

This research underscores the potential for subtle logic bugs to undermine even memory-safe software, emphasizing the importance of ongoing scrutiny and enhancement in the security design of credential vaulting solutions.

## Similar posts on daily.dev

- [Don’t just attend KubeCon \+ CloudNativeCon, Merge Forward your experience\!](https://daily.dev/posts/don-t-just-attend-kubecon-cloudnativecon-merge-forward-your-experience--l0rpp73x8) · CNCF · 1 upvotes · 0 comments
- [Announcing H2 2026 KCDs](https://daily.dev/posts/announcing-h2-2026-kcds-m96goajm1) · CNCF · 1 upvotes · 0 comments
- [Two months of Open Community Groups](https://daily.dev/posts/two-months-of-open-community-groups-asf52zhbs) · CNCF · 0 upvotes · 0 comments
- [CNCF Unveils Schedule for KubeCon \+ CloudNativeCon Europe 2026](https://daily.dev/posts/cncf-unveils-schedule-for-kubecon-cloudnativecon-europe-2026-ikhcoa5cb) · CNCF · 2 upvotes · 0 comments
- [CNCF Debuts KubeCon \+ CloudNativeCon Japan 2026 Schedule](https://daily.dev/posts/cncf-debuts-kubecon-cloudnativecon-japan-2026-schedule-xp5pyudub) · CNCF · 1 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#authentication](https://daily.dev/tags/authentication), [#vulnerability](https://daily.dev/tags/vulnerability), [#hashicorp](https://daily.dev/tags/hashicorp), [#zero-day](https://daily.dev/tags/zero-day)

[View this post on daily.dev](https://daily.dev/posts/security-researchers-uncover-zero-day-vulnerabilities-in-hashicorp-vault-peqvmxapd)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Security Researchers Uncover Zero-Day Vulnerabilities in HashiCorp Vault","url":"https://daily.dev/posts/security-researchers-uncover-zero-day-vulnerabilities-in-hashicorp-vault-peqvmxapd","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/security-researchers-uncover-zero-day-vulnerabilities-in-hashicorp-vault-peqvmxapd"},"datePublished":"2025-08-07T10:16:11.036Z","dateModified":"2025-08-07T10:55:39.990Z","description":"Security researchers discovered 14 critical vulnerabilities in HashiCorp Vault and CyberArk Conjur, including authentication bypasses, MFA evasion, privilege...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/020ec534f55e9abec67514e1529cbb67?_a=AQAEulh","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/020ec534f55e9abec67514e1529cbb67?_a=AQAEulh","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/security-researchers-uncover-zero-day-vulnerabilities-in-hashicorp-vault-peqvmxapd","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,authentication,vulnerability,hashicorp,zero-day","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"Security Researchers Uncover Zero-Day Vulnerabilities in HashiCorp Vault"}]}
```

