CVE-2024-7594
Vault’s SSH secrets engine did not require the valid_principals list to contain a value by default. If the valid_principals and default_user fields of the SSH secrets engine configuration are not set, an SSH certificate requested by an authorized user to Vault’s SSH secrets engine could be used to authenticate as any user on the host. Fixed in Vault Community Edition 1.17.6, and in Vault Enterprise 1.17.6, 1.16.10, and 1.15.15.
Published:Sep 26, 2024
Last Modified:Nov 13, 2025
EPS:Sep 26, 2024
EPSS Score:0.00539
CVSS Score:7.5
Affected Products
Vendor
Product
Action
Vendor
Hashicorp
Product
Vault
Hashicorp
Vault
Vendor
Hashicorp
Product
Vault Community Edition
Hashicorp
Vault Community Edition
Vendor
Hashicorp
Product
Vault Enterprise
Hashicorp
Vault Enterprise
Vendor
Openbao
Product
Openbao
Openbao
Openbao
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
