A Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. Six years running.Six years. Gartner® Magic Quadrant™ Leader.Find Out Why
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2025-13357

CVE-2025-13357: Terraform Provider Auth Bypass Flaw

CVE-2025-13357 is an authentication bypass vulnerability in HashiCorp Vault's Terraform Provider affecting LDAP auth configurations. Attackers could bypass authentication on misconfigured systems. This article covers technical details, affected versions, impact, and mitigation strategies.

Published: March 11, 2026

CVE-2025-13357 Overview

CVE-2025-13357 is an insecure default configuration vulnerability in HashiCorp Vault's Terraform Provider that affects the LDAP authentication method. The provider incorrectly set the default deny_null_bind parameter to false, potentially allowing authentication bypass when the underlying LDAP server permits anonymous or unauthenticated binds. This misconfiguration could enable attackers to bypass authentication controls and gain unauthorized access to Vault secrets.

Critical Impact

Attackers exploiting this vulnerability could bypass authentication entirely, gaining unauthorized access to secrets, credentials, and sensitive data managed by HashiCorp Vault without valid credentials.

Affected Products

  • HashiCorp Terraform Provider for Vault (versions prior to v5.5.0)
  • HashiCorp Vault deployments using LDAP authentication configured via Terraform
  • Organizations with LDAP servers that allow anonymous or unauthenticated binds

Discovery Timeline

  • 2025-11-21 - CVE-2025-13357 published to NVD
  • 2025-12-10 - Last updated in NVD database

Technical Details for CVE-2025-13357

Vulnerability Analysis

This vulnerability stems from an insecure default configuration (CWE-1188) in the HashiCorp Vault Terraform Provider. The LDAP authentication method relies on a parameter called deny_null_bind to prevent authentication attempts with empty or null credentials. When this parameter is set to false, the system may accept authentication requests without proper credential validation.

The impact is significant when combined with LDAP servers that allow anonymous binds. In such configurations, an attacker can submit authentication requests with null or empty credentials and successfully authenticate to Vault, bypassing all authentication controls. This grants the attacker access to secrets and sensitive data stored within Vault without requiring legitimate credentials.

Root Cause

The root cause of CVE-2025-13357 is an incorrect default value assignment in the Terraform Provider's LDAP authentication backend configuration. The deny_null_bind parameter was set to false by default instead of true. In production environments where LDAP servers are configured to accept anonymous binds (which is more common than expected for legacy compatibility reasons), this default creates an authentication bypass condition.

The Terraform Provider should have defaulted to the more secure option of deny_null_bind = true, which would reject any authentication attempts with null or empty bind credentials, regardless of the underlying LDAP server's configuration.

Attack Vector

The attack can be executed remotely over the network without requiring any privileges or user interaction. An attacker targeting a vulnerable Vault deployment would:

  1. Identify a Vault instance using LDAP authentication configured via the affected Terraform Provider versions
  2. Determine that the underlying LDAP server accepts anonymous or null binds
  3. Submit an authentication request to Vault's LDAP auth endpoint with empty or null credentials
  4. Successfully authenticate due to the permissive deny_null_bind setting
  5. Access secrets and sensitive data within Vault based on the default or associated policies

The exploitation relies on the combination of the insecure Terraform Provider default and an LDAP server configuration that permits anonymous binds. Organizations that have explicitly set deny_null_bind = true in their Terraform configurations are not affected.

Detection Methods for CVE-2025-13357

Indicators of Compromise

  • LDAP authentication attempts with empty usernames or null credentials in Vault audit logs
  • Unusual authentication patterns from unrecognized IP addresses to the LDAP auth method
  • Vault token generation events without corresponding valid user credentials
  • Access to sensitive paths by accounts that should not have permissions

Detection Strategies

  • Review Terraform state files and configurations to identify LDAP auth backends without explicit deny_null_bind = true settings
  • Audit Vault's LDAP authentication method configuration using vault read auth/ldap/config to verify current deny_null_bind status
  • Implement log monitoring for authentication events with missing or empty username fields
  • Deploy network monitoring to detect abnormal authentication traffic patterns to Vault's LDAP endpoints

Monitoring Recommendations

  • Enable and centralize Vault audit logs to capture all authentication attempts
  • Configure alerts for LDAP authentication failures and anomalies
  • Monitor for changes to LDAP auth method configurations in Vault
  • Implement real-time monitoring of Terraform state changes affecting Vault resources

How to Mitigate CVE-2025-13357

Immediate Actions Required

  • Upgrade HashiCorp Vault Terraform Provider to version v5.5.0 or later immediately
  • Review existing Terraform configurations for LDAP auth backends and explicitly set deny_null_bind = true
  • Audit LDAP server configurations to disable anonymous bind capabilities where possible
  • Review Vault audit logs for any evidence of exploitation prior to remediation

Patch Information

HashiCorp has released Terraform Provider version v5.5.0 that corrects the default value of deny_null_bind to true, ensuring secure-by-default configurations. Organizations should update their Terraform Provider version and re-apply configurations to remediate this vulnerability. For detailed patch information, see the HashiCorp Security Advisory HCSEC-2025-33.

Workarounds

  • Explicitly set deny_null_bind = true in all LDAP auth backend Terraform configurations before upgrading
  • Disable anonymous binds on LDAP servers at the directory service level
  • Implement network segmentation to restrict access to Vault's authentication endpoints
  • Deploy additional authentication controls such as IP allowlisting for Vault access
hcl
# Secure LDAP auth backend configuration
resource "vault_ldap_auth_backend" "ldap" {
  path        = "ldap"
  url         = "ldaps://ldap.example.com"
  binddn      = "cn=vault,ou=services,dc=example,dc=com"
  bindpass    = var.ldap_bind_password
  userdn      = "ou=users,dc=example,dc=com"
  userattr    = "uid"
  groupdn     = "ou=groups,dc=example,dc=com"
  groupattr   = "cn"
  
  # Critical: Explicitly set to true to prevent null bind authentication bypass
  deny_null_bind = true
}

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypeAuth Bypass

  • Vendor/TechHashicorp Terraform Provider

  • SeverityCRITICAL

  • CVSS Score9.8

  • EPSS Probability0.08%

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Impact Assessment
  • ConfidentialityLow
  • IntegrityNone
  • AvailabilityHigh
  • CWE References
  • CWE-1188
  • Vendor Resources
  • HashiCorp Security Advisory HCSEC-2025-33
  • Latest CVEs
  • CVE-2025-11956: OBS Student Affairs System XSS Flaw

  • CVE-2026-49199: Acer Predator Connect W6x Firmware RCE Flaw

  • CVE-2026-46344: Openquantumsafe Liboqs DOS Vulnerability

  • CVE-2026-44518: Openquantumsafe Liboqs DoS Vulnerability
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English