Arbitrary Remote Code Execution via Plugin Catalog Abuse
Published Aug 1, 2025
9.1
CRITICALCVSS 3.1
EPSS 0.91%
Description
A privileged Vault operator within the root namespace with write permission to {{sys/audit}} may obtain code execution on the underlying host if a plugin directory is set in Vault’s configuration. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.
Affected products
-
- Version 0.8.0StatusaffectedConstraints<1.20.1
- Version
-
- Version 0.8.0StatusaffectedConstraints<1.20.1
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| HashiCorp | Vault | unaffected |
| ||||||
| HashiCorp | Vault Enterprise | unaffected |
|
No data.
Red Hat Openshift Data Foundation 4
odf4/cephcsi-rhel9
Not affected
Red Hat Openshift Data Foundation 4
odf4/mcg-cli-rhel9
Not affected
Red Hat Openshift Data Foundation 4
odf4/mcg-rhel9-operator
Not affected
Red Hat Openshift Data Foundation 4
odf4/odf-cli-rhel9
Not affected
Red Hat Trusted Artifact Signer
rhtas/client-server-rhel9
Not affected
Red Hat Trusted Artifact Signer
rhtas/fulcio-rhel9
Not affected
cert-manager Operator for Red Hat OpenShift
cert-manager/cert-manager-operator-rhel9
Affected
cert-manager Operator for Red Hat OpenShift
cert-manager/jetstack-cert-manager-acmesolver-rhel9
Affected
cert-manager Operator for Red Hat OpenShift
cert-manager/jetstack-cert-manager-rhel9
Affected
external secrets operator for Red Hat OpenShift - Tech Preview
external-secrets-operator/external-secrets-operator-rhel9
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Openshift Data Foundation 4 | odf4/cephcsi-rhel9 | Not affected | n/a |
| Red Hat Openshift Data Foundation 4 | odf4/mcg-cli-rhel9 | Not affected | n/a |
| Red Hat Openshift Data Foundation 4 | odf4/mcg-rhel9-operator | Not affected | n/a |
| Red Hat Openshift Data Foundation 4 | odf4/odf-cli-rhel9 | Not affected | n/a |
| Red Hat Trusted Artifact Signer | rhtas/client-server-rhel9 | Not affected | n/a |
| Red Hat Trusted Artifact Signer | rhtas/fulcio-rhel9 | Not affected | n/a |
| cert-manager Operator for Red Hat OpenShift | cert-manager/cert-manager-operator-rhel9 | Affected | n/a |
| cert-manager Operator for Red Hat OpenShift | cert-manager/jetstack-cert-manager-acmesolver-rhel9 | Affected | n/a |
| cert-manager Operator for Red Hat OpenShift | cert-manager/jetstack-cert-manager-rhel9 | Affected | n/a |
| external secrets operator for Red Hat OpenShift - Tech Preview | external-secrets-operator/external-secrets-operator-rhel9 | Not affected | n/a |
github.com/hashicorp/vault
Go
Introduced 0.8.0 Fixed 1.20.1
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/hashicorp/vault | 0.8.0 | 1.20.1 |
Remediation
Red Hat statement
The impact has been set to Important rather than Critical as this vulnerability requires a privileged user with write access to sys/audit in the root namespace. The execution also requires the SHA256 digest of the target file, which makes the attack complexity high. However, a malicious operator can possibly reproduce the file’s contents and compute its hash using the sys/audit-hash endpoint.
Red Hat mitigation
No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
1 other source (Red Hat) ▾
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Aug 1, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2025–2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.91% (0.00913) | 58.60th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.87% (0.00873) | 54.02th | v5 (v2026.06.15) |
| Aug 2, 2025 | 0.07% (0.00072) | 22.69th | v4 (v2025.03.14) |
References (6)
- https://access.redhat.com/security/cve/CVE-2025-6000 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2386014 Issue Tracking
- https://discuss.hashicorp.com/t/hcsec-2025-14-privileged-vault-operator-may-execute-code-on-the-underlying-host/76033 Vendor Advisory
- https://github.com/advisories/GHSA-mr4h-qf9j-f665 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-6000
- https://www.cve.org/CVERecord?id=CVE-2025-6000
Change history (0)
No recorded changes yet.