# Vault Userpass and LDAP lockout bypass via username case

Source: https://startwithidentity.com/cves/cve-2025-6004/
Last updated: 2026-08-29
License: content by Start with Identity. Cite the source URL.

---

## What broke

Vault's Userpass and LDAP auth methods counted lockout per exact string but accepted login on a case-insensitive match. `Admin`, `admin`, and `ADMIN` were three lockout buckets and one account. CVSS 5.3. Fixed in 1.20.2.

## Why it matters

Lockout is the control that makes password auth survivable. A case-permutation bypass is a brute-force enabler on the box that holds the rest of your secrets. Pair with the username-enumeration pair ([CVE-2025-6010](https://startwithidentity.com/cves/cve-2025-6010/), [CVE-2025-6011](https://startwithidentity.com/cves/cve-2025-6011/)).

## What to do

- Upgrade. Then normalize usernames to a single case in the auth method.
- Prefer [phishing-resistant](https://startwithidentity.com/glossary/phishing-resistant-mfa/) or cert auth for humans who can reach Vault.

## After you patch

A vault compromise is not one credential, it is every credential the vault held or could issue.

- **Rotate everything in scope**, including secrets the vault issued dynamically during the exposure window, because a lease that was valid then may still be valid now.
- **Revoke active leases and tokens**, then review the audit device log for reads you cannot attribute to a known workload.
- **Rotate the vault's own credentials**: unseal or recovery keys, root tokens, and any authentication backend configuration that could be used to re-enter.
- **Rotate downstream credentials the vault brokered**, cloud roles, database users, and PKI certificates, since the point of the vault is that it can mint them. See [secrets rotation](https://startwithidentity.com/glossary/secrets-rotation/) and [what is secrets management](https://startwithidentity.com/guides/fundamentals/what-is-secrets-management/).

## Sources

- [NVD: CVE-2025-6004](https://nvd.nist.gov/vuln/detail/CVE-2025-6004)
