Start with Identity
Protocol · 15 briefs

Secrets-manager identity CVEs

A secrets manager is an identity provider for machines. Bypass the authenticator and you do not steal one secret. You become every workload that would have checked one out.

How this protocol fails

Cyata's 2025 Black Hat work on CyberArk Conjur and HashiCorp Vault is the chapter heading. Conjur's IAM authenticator could be pointed at an attacker STS, then chained to template RCE. VaultFault delivered the first public Vault RCE plus MFA, lockout, cert-auth, and EntityID failures. 2023 already had LDAP username enumeration on Vault. Identity teams own these boxes even when AppSec files the ticket.

What security people should do

  • Upgrade Vault to 1.20.2+ and Conjur OSS to 1.22.1+ / Secrets Manager 13.6.1+. Take the whole advisory train, not one CVE.
  • Rotate every secret the manager held if the authenticator was reachable while vulnerable.
  • Restrict plugin catalogs and policy-name writes. Those are root on the secrets plane.
  • Prefer cert or OIDC for humans. LDAP+MFA on Vault has now failed this test twice.

CVEs in this category

15
Secrets managers
0
On CISA KEV
0
Actively exploited
15
Showing
Severity
Year
Status

Showing 15 of 15

Working this protocol in production and see a brief we should add or correct? Email [email protected] or volunteer as a CVE Analyst.