PT-2025-33679 · Vaultls · Vaultls
7Ritn
·
Published
2025-08-18
·
Updated
2025-08-23
·
CVE-2025-55299
CVSS v3.1
9.4
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions:
VaulTLS versions prior to 0.9.1
Description:
VaulTLS is a solution for managing mTLS (mutual TLS) certificates. User accounts created through the User web UI have an empty password set, allowing attackers to log in with a blank password. Previously, disabling password-based login only affected the frontend, but login via the API remained possible.
Recommendations:
Update to version 0.9.1 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vaultls