PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-55770 openbao CVE debrief

OpenBao, an open-source identity-based secrets management system, had a vulnerability prior to version 2.5.5. The system used EscapeLDAPValue, an RFC 4514 distinguished-name escaping function, where RFC 4515 LDAP search-filter escaping was required. This allowed an attacker-controlled username containing filter metacharacters to alter the search predicate and select a different directory entry. A resulting token could be associated with another LDAP identity and gain access to secrets, policies, or modification capabilities assigned to that identity. The issue is fixed in version 2.5.5.

Vendor
openbao
Product
Unknown
CVSS
MEDIUM 6.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-15
Original CVE updated
2026-09-29
Advisory published
2026-09-15
Advisory updated
2026-09-29

Who should care

Defenders using OpenBao with LDAP authentication, especially those with Active Directory UPNDomain or UserDN and UserAttr binding, should assess exposure and prioritize verification and remediation.

Why it matters

Defenders should care about CVE-2026-55770 because it allows an attacker-controlled username to alter the search predicate and gain access to secrets, policies, or modification capabilities assigned to another LDAP identity. This requires verification of OpenBao version and LDAP authentication configuration, and potential remediation through upgrade or compensating controls.

  • Potential unauthorized access to secrets, policies, or modification capabilities assigned to another LDAP identity
  • Possible alteration of search predicates to select a different directory entry
  • Required verification of OpenBao version and LDAP authentication configuration
  • Potential need for compensating controls if upgrade is not feasible

Technical summary

The OpenBao system used EscapeLDAPValue, an RFC 4514 distinguished-name escaping function, where RFC 4515 LDAP search-filter escaping was required. This allowed an attacker-controlled username containing filter metacharacters to alter the search predicate and select a different directory entry. As a result, a token could be associated with another LDAP identity, potentially granting access to secrets, policies, or modification capabilities assigned to that identity. The issue is fixed in version 2.5.5, and defenders should prioritize verifying and upgrading to this version or later, especially if using LDAP authentication with Active Directory UPNDomain or UserDN and UserAttr binding.

Defensive priority

Defenders should prioritize verifying and upgrading to OpenBao version 2.5.5 or later, especially if using LDAP authentication with Active Directory UPNDomain or UserDN and UserAttr binding.

Recommended defensive actions

  • Verify OpenBao version and upgrade to 2.5.5 or later if necessary
  • Review LDAP authentication configuration for Active Directory UPNDomain or UserDN and UserAttr binding
  • Monitor for suspicious activity and implement compensating controls if upgrade is not feasible
  • Perform vulnerability scanning to identify potentially exposed systems
  • Review system logs for signs of exploitation
  • Implement additional security controls such as multi-factor authentication
  • Conduct a thorough risk assessment to identify potential impacts

Evidence notes

The CVE record and source references provide details on the vulnerability and its fix. However, the corpus does not establish versions, exploitation, impact, or remediation beyond the provided information, requiring verification from official sources.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-55770 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-55770

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-55770 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-55770

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.