{"id":"CVE-2025-55001","aliases":["BIT-openbao-2025-55001","GHSA-2q8q-8fgw-9p6p","GO-2025-3859"],"url":"https://o3.security/vulnerability/CVE-2025-55001","summary":"OpenBao LDAP MFA Enforcement Bypass When Using Username As Alias","details":"### Impact\n\nOpenBao allows assignment of policies and MFA attribution based upon entity aliases, chosen by the underlying auth method. When using the `username_as_alias=true` parameter in the LDAP auth method, the caller-supplied username is used verbatim without normalization, allowing an attacker to bypass alias-specific MFA requirements.\n\n### Patches\n\nOpenBao v2.3.2 will patch this issue.\n\n### Workarounds\n\nLDAP methods are only vulnerable if using `username_as_alias=true`. Remove all usage of this parameter and update any entity aliases accordingly.\n\n### References\n\nThis issue was disclosed to HashiCorp and is the OpenBao equivalent of the following tickets:\n\n- https://discuss.hashicorp.com/t/hcsec-2025-20-vault-ldap-mfa-enforcement-bypass-when-using-username-as-alias/76092\n- https://nvd.nist.gov/vuln/detail/CVE-2025-6013","published":"2025-08-09T02:01:29.056Z","modified":"2026-08-12T03:51:30.633026788Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/openbao/openbao","fixedVersion":"2.3.2"},{"ecosystem":"Go","name":"github.com/openbao/openbao","fixedVersion":"0.0.0-20250807212521-c52795c1ef74"}],"fix":{"url":"https://github.com/openbao/openbao/commit/c52795c1ef746c7f2c510f9225aa8ccbbd44f9fc","label":"openbao/openbao@c52795c"},"references":[{"type":"WEB","url":"https://discuss.hashicorp.com/t/hcsec-2025-20-vault-ldap-mfa-enforcement-bypass-when-using-username-as-alias/76092"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/55xxx/CVE-2025-55001.json"},{"type":"ADVISORY","url":"https://github.com/openbao/openbao/security/advisories/GHSA-2q8q-8fgw-9p6p"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-55001"},{"type":"FIX","url":"https://github.com/openbao/openbao/commit/c52795c1ef746c7f2c510f9225aa8ccbbd44f9fc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-6013"},{"type":"PACKAGE","url":"https://github.com/openbao/openbao"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:30.633026788Z"}}