← Vulnerability feed

Vulnerability record · CVE-2022-40186 · published 22 September 2022

CVE-2022-40186: Hashicorp vault insecure direct object reference vulnerability

Hashicorp · Vault

An issue was discovered in HashiCorp Vault and Vault Enterprise before 1.11.3. A vulnerability in the Identity Engine was found where, in a deployment where an entity has multiple mount accessors with shared alias names, Vault may overwrite metadata to the wrong alias due to an issue with checking the proper alias assigned to an entity. This may allow for unintended access to key/value paths using that metadata in Vault.

9.1 CVSS 3.1 Critical EPSS 1.00% · top 38.8% CWE-639 · Insecure direct object reference
9.1CVSS 3.1 base score
1.00%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

An issue was discovered in HashiCorp Vault and Vault Enterprise before 1.11.3. A vulnerability in the Identity Engine was found where, in a deployment where an entity has multiple mount accessors with shared alias names, Vault may overwrite metadata to the wrong alias due to an issue with checking the proper alias assigned to an entity. This may allow for unintended access to key/value paths using that metadata in Vault.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-40186 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-2048Hashicorp vault improper certificate validation vulnerabilityVault and Vault Enterprise (“Vault”) TLS certificate auth method did not correctly validate client certificates when configured with a non-CA certifi…EPSS 0.45%9.8CVE-2020-35192Hashicorp vault missing authentication for critical function vulnerabilityThe official vault docker images before 0.11.6 contain a blank password for a root user. System using the vault docker container deployed by affected…EPSS 2.9%9.8CVE-2020-12757Hashicorp vault improper privilege management vulnerabilityHashiCorp Vault and Vault Enterprise 1.4.0 and 1.4.1, when configured with the GCP Secrets Engine, may incorrectly generate GCP Credentials with the …EPSS 1.5%9.1CVE-2025-6000Hashicorp vault code injection vulnerabilityA privileged Vault operator within the root namespace with write permission to {{sys/audit}} may obtain code execution on the underlying host if a pl…EPSS 0.91%9.1CVE-2022-36129Hashicorp vault missing authentication for critical function vulnerabilityHashiCorp Vault Enterprise 1.7.0 through 1.9.7, 1.10.4, and 1.11.0 clusters using Integrated Storage expose an unauthenticated API endpoint that coul…EPSS 1.6%9.1CVE-2020-10661Hashicorp vault vulnerabilityHashiCorp Vault and Vault Enterprise versions 0.11.0 through 1.3.3 may, under certain circumstances, have existing nested-path policies grant access …EPSS 1.1%8.8CVE-2026-4525Hashicorp vault vulnerabilityIf a Vault auth mount is configured to pass through the "Authorization" header, and the "Authorization" header is used to authenticate to Vault, Vaul…EPSS 0.59%8.8CVE-2025-3879Hashicorp vault incorrect authorization vulnerabilityVault Community, Vault Enterprise (“Vault”) Azure Auth method did not correctly validate the claims in the Azure-issued token, resulting in the poten…EPSS 0.42%

Source: NIST National Vulnerability Database (record CVE-2022-40186), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.