PT-2025-33679 · Vaultls · Vaultls

7Ritn

·

Published

2025-08-18

·

Updated

2025-08-23

·

CVE-2025-55299

CVSS v3.1

9.4

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions: VaulTLS versions prior to 0.9.1
Description: VaulTLS is a solution for managing mTLS (mutual TLS) certificates. User accounts created through the User web UI have an empty password set, allowing attackers to log in with a blank password. Previously, disabling password-based login only affected the frontend, but login via the API remained possible.
Recommendations: Update to version 0.9.1 or later.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-55299
GHSA-PJFR-PJ3H-CW8M

Affected Products

Vaultls