CVE-2022-40186 - CVE House
Back to Database
Status published Unknown CVE-2022-40186

An issue was discovered in HashiCorp Vault and Vault Enterprise...

Vulnerability Description

An issue was discovered in HashiCorp Vault and Vault Enterprise before 1.11.3. A vulnerability in the Identity Engine was found where, in a deployment where an entity has multiple mount accessors with shared alias names, Vault may overwrite metadata to the wrong alias due to an issue with checking the proper alias assigned to an entity. This may allow for unintended access to key/value paths using that metadata in Vault.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-40186

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

vault
Vulnerable Versions:
1.8.0, 1.10.0, 1.11.0

Timeline

Official Publish: September 22nd, 2022
Last Modified: May 27th, 2025
Added to House: July 21st, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.