PatchSiren cyber security CVE debrief
CVE-2026-55770 openbao CVE debrief
OpenBao, an open-source identity-based secrets management system, had a vulnerability prior to version 2.5.5. The system used EscapeLDAPValue, an RFC 4514 distinguished-name escaping function, where RFC 4515 LDAP search-filter escaping was required. This allowed an attacker-controlled username containing filter metacharacters to alter the search predicate and select a different directory entry. A resulting token could be associated with another LDAP identity and gain access to secrets, policies, or modification capabilities assigned to that identity. The issue is fixed in version 2.5.5.
- Vendor
- openbao
- Product
- Unknown
- CVSS
- MEDIUM 6.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-15
- Original CVE updated
- 2026-09-29
- Advisory published
- 2026-09-15
- Advisory updated
- 2026-09-29
Who should care
Defenders using OpenBao with LDAP authentication, especially those with Active Directory UPNDomain or UserDN and UserAttr binding, should assess exposure and prioritize verification and remediation.
Why it matters
Defenders should care about CVE-2026-55770 because it allows an attacker-controlled username to alter the search predicate and gain access to secrets, policies, or modification capabilities assigned to another LDAP identity. This requires verification of OpenBao version and LDAP authentication configuration, and potential remediation through upgrade or compensating controls.
- Potential unauthorized access to secrets, policies, or modification capabilities assigned to another LDAP identity
- Possible alteration of search predicates to select a different directory entry
- Required verification of OpenBao version and LDAP authentication configuration
- Potential need for compensating controls if upgrade is not feasible
Technical summary
The OpenBao system used EscapeLDAPValue, an RFC 4514 distinguished-name escaping function, where RFC 4515 LDAP search-filter escaping was required. This allowed an attacker-controlled username containing filter metacharacters to alter the search predicate and select a different directory entry. As a result, a token could be associated with another LDAP identity, potentially granting access to secrets, policies, or modification capabilities assigned to that identity. The issue is fixed in version 2.5.5, and defenders should prioritize verifying and upgrading to this version or later, especially if using LDAP authentication with Active Directory UPNDomain or UserDN and UserAttr binding.
Defensive priority
Defenders should prioritize verifying and upgrading to OpenBao version 2.5.5 or later, especially if using LDAP authentication with Active Directory UPNDomain or UserDN and UserAttr binding.
Recommended defensive actions
- Verify OpenBao version and upgrade to 2.5.5 or later if necessary
- Review LDAP authentication configuration for Active Directory UPNDomain or UserDN and UserAttr binding
- Monitor for suspicious activity and implement compensating controls if upgrade is not feasible
- Perform vulnerability scanning to identify potentially exposed systems
- Review system logs for signs of exploitation
- Implement additional security controls such as multi-factor authentication
- Conduct a thorough risk assessment to identify potential impacts
Evidence notes
The CVE record and source references provide details on the vulnerability and its fix. However, the corpus does not establish versions, exploitation, impact, or remediation beyond the provided information, requiring verification from official sources.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-55770 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-55770
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-55770 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-55770
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/openbao/openbao/commit/10b7825c714c1ef25b6c3c1c2cd6ecd8747c0659
-
Source reference
Unverified legacy reference
URL: https://github.com/openbao/openbao/commit/8077f96bdc02137b0a072146b6f9ca11c96c549c
-
Source reference
Unverified legacy reference
URL: https://github.com/openbao/openbao/pull/3306
-
Source reference
Unverified legacy reference
URL: https://github.com/openbao/openbao/pull/3313
-
Source reference
Unverified legacy reference
URL: https://github.com/openbao/openbao/releases/tag/v2.5.5
-
Source reference
Unverified legacy reference
URL: https://github.com/openbao/openbao/releases/tag/v2.6.0
-
Source reference
Unverified legacy reference
URL: https://github.com/openbao/openbao/security/advisories/GHSA-6mwx-4547-5vc9
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.