← Vulnerability feed

Vulnerability record · CVE-2024-7594 · published 26 September 2024

CVE-2024-7594: Hashicorp vault incorrect permission assignment vulnerability

Hashicorp · Vault

Vault’s SSH secrets engine did not require the valid_principals list to contain a value by default. If the valid_principals and default_user fields of the SSH secrets engine configuration are not set, an SSH certificate requested by an authorized user to Vault’s SSH secrets engine could be used to authenticate as any user on the host. Fixed in Vault Community Edition 1.17.6, and in Vault Enterprise 1.17.6, 1.16.10, and 1.15.15.

8.8 CVSS 3.1 High EPSS 0.27% · top 82.9% CWE-732 · Incorrect permission assignment
8.8CVSS 3.1 base score
0.27%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Vault’s SSH secrets engine did not require the valid_principals list to contain a value by default. If the valid_principals and default_user fields of the SSH secrets engine configuration are not set, an SSH certificate requested by an authorized user to Vault’s SSH secrets engine could be used to authenticate as any user on the host. Fixed in Vault Community Edition 1.17.6, and in Vault Enterprise 1.17.6, 1.16.10, and 1.15.15.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-7594 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-2048Hashicorp vault improper certificate validation vulnerabilityVault and Vault Enterprise (“Vault”) TLS certificate auth method did not correctly validate client certificates when configured with a non-CA certifi…EPSS 0.45%9.8CVE-2020-35192Hashicorp vault missing authentication for critical function vulnerabilityThe official vault docker images before 0.11.6 contain a blank password for a root user. System using the vault docker container deployed by affected…EPSS 2.9%9.8CVE-2020-12757Hashicorp vault improper privilege management vulnerabilityHashiCorp Vault and Vault Enterprise 1.4.0 and 1.4.1, when configured with the GCP Secrets Engine, may incorrectly generate GCP Credentials with the …EPSS 1.5%9.4CVE-2026-33758Openbao improper input validation vulnerabilityOpenBao is an open source identity-based secrets management system. Prior to version 2.5.2, OpenBao installations that have an OIDC/JWT authenticatio…EPSS 0.45%9.1CVE-2025-54997Openbao code injection vulnerabilityOpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions …EPSS 0.38%9.1CVE-2025-6000Hashicorp vault code injection vulnerabilityA privileged Vault operator within the root namespace with write permission to {{sys/audit}} may obtain code execution on the underlying host if a pl…EPSS 0.91%9.1CVE-2022-40186Hashicorp vault insecure direct object reference vulnerabilityAn issue was discovered in HashiCorp Vault and Vault Enterprise before 1.11.3. A vulnerability in the Identity Engine was found where, in a deploymen…EPSS 1.00%9.1CVE-2022-36129Hashicorp vault missing authentication for critical function vulnerabilityHashiCorp Vault Enterprise 1.7.0 through 1.9.7, 1.10.4, and 1.11.0 clusters using Integrated Storage expose an unauthenticated API endpoint that coul…EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2024-7594), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.