CVE-2025-6014
Vault and Vault Enterprise’s (“Vault”) TOTP Secrets Engine code validation endpoint is susceptible to code reuse within its validity period. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS probability
- 0.36%
- CWE
- CWE-156
- Published
- 2025-08-01
- Last modified
- 2026-03-12
Affected products
- HashiCorp Vault
- HashiCorp Vault Enterprise
Weakness type
Related vulnerabilities
- CVE-2025-55001 — OpenBao LDAP MFA Enforcement Bypass When Using Username As Alias
- CVE-2025-55000 — OpenBao TOTP Secrets Engine Enables Code Reuse
- CVE-2025-6013 — Vault LDAP MFA Enforcement Bypass When Using Username As Alias