# HashiCorp Vault LDAP auth username enumeration

Source: https://startwithidentity.com/cves/cve-2023-3462/
Last updated: 2026-08-29
License: content by Start with Identity. Cite the source URL.

---

## What broke

[HashiCorp Vault](https://startwithidentity.com/vendors/machine-identity/hashicorp-vault/)'s LDAP auth method leaked whether a username existed. Different error (or timing) for unknown vs known. Fixed in Vault 1.14.1 and the matching Enterprise line. The 2025 VaultFault set ([CVE-2025-6010](https://startwithidentity.com/cves/cve-2025-6010/), [CVE-2025-6004](https://startwithidentity.com/cves/cve-2025-6004/), [CVE-2025-6003](https://startwithidentity.com/cves/cve-2025-6003/)) is this control failing again, then chaining into lockout and MFA bypass.

## Why it matters

Enumeration on a human-reachable Vault UI is how brute force becomes targeted. 2023's "medium" LDAP leak is the first chapter of 2025's Vault identity story.

## What to do

- You should already be far past 1.14.1. If an old 1.12/1.13 Community box is still up, it is also in the VaultFault blast radius.
- Prefer cert or OIDC for humans. Do not offer LDAP Userpass on the internet.
- Confirm login errors are identical for unknown and known users after you upgrade.

## After you patch

A vault compromise is not one credential, it is every credential the vault held or could issue.

- **Rotate everything in scope**, including secrets the vault issued dynamically during the exposure window, because a lease that was valid then may still be valid now.
- **Revoke active leases and tokens**, then review the audit device log for reads you cannot attribute to a known workload.
- **Rotate the vault's own credentials**: unseal or recovery keys, root tokens, and any authentication backend configuration that could be used to re-enter.
- **Rotate downstream credentials the vault brokered**, cloud roles, database users, and PKI certificates, since the point of the vault is that it can mint them. See [secrets rotation](https://startwithidentity.com/glossary/secrets-rotation/) and [what is secrets management](https://startwithidentity.com/guides/fundamentals/what-is-secrets-management/).

## Sources

- [NVD: CVE-2023-3462](https://nvd.nist.gov/vuln/detail/CVE-2023-3462)
- HashiCorp Vault 1.14.1 release notes
