VaulTLS is a modern solution for managing mTLS (mutual TLS) certificates. Prior to 0.9.1, user accounts created through the User web UI have an empty but not NULL password set, attackers can use this to login with an empty password. This is combined with that fact, that previously disabling the password based login only effected the frontend, but still allowed login via the API. This vulnerability is fixed in 0.9.1.
Metrics
Affected Vendors & Products
References
History
Mon, 18 Aug 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 18 Aug 2025 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | VaulTLS is a modern solution for managing mTLS (mutual TLS) certificates. Prior to 0.9.1, user accounts created through the User web UI have an empty but not NULL password set, attackers can use this to login with an empty password. This is combined with that fact, that previously disabling the password based login only effected the frontend, but still allowed login via the API. This vulnerability is fixed in 0.9.1. | |
Title | VaulTLS has a password-based login exploit in additional user accounts | |
Weaknesses | CWE-521 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-08-18T17:36:28.462Z
Updated: 2025-08-18T17:54:17.654Z
Reserved: 2025-08-12T16:15:30.238Z
Link: CVE-2025-55299

Updated: 2025-08-18T17:54:09.049Z

Status : Awaiting Analysis
Published: 2025-08-18T18:15:40.023
Modified: 2025-08-18T20:16:28.750
Link: CVE-2025-55299

No data.