PatchSiren cyber security CVE debrief
CVE-2026-63131 openbao CVE debrief
OpenBao, an open-source identity-based secrets management system, had an issue where a broader wildcard ACL grant could be evaluated before more-specific trailing-wildcard ACL paths with capabilities = [deny] for a LIST operation. This could allow listing a denied path if a parent path permitted LIST and a child path was denied. The issue is fixed in version 2.6.0.
- Vendor
- openbao
- Product
- Unknown
- CVSS
- MEDIUM 6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-23
- Original CVE updated
- 2026-09-29
- Advisory published
- 2026-09-23
- Advisory updated
- 2026-09-29
Who should care
Defenders managing OpenBao deployments, especially those with LIST operations and ACL configurations, should assess exposure and prioritize upgrading to version 2.6.0 or later. They should also review ACL configurations to prevent unauthorized LIST operations and verify OpenBao deployments.
Why it matters
Defenders should prioritize verifying and upgrading OpenBao to version 2.6.0 or later, assess exposure in their environment, and review ACL configurations to prevent unauthorized LIST operations.
- Verify and upgrade OpenBao to version 2.6.0 or later
- Assess and update ACL configurations to prevent unauthorized LIST operations
- Review environment for exposure to this issue
Technical summary
The issue in OpenBao's vault/policy/acl.go could evaluate a broader wildcard ACL grant before more-specific trailing-wildcard ACL paths with capabilities = [deny] for a LIST operation, potentially allowing listing of denied paths. This issue allows listing a denied path if a parent path permitted LIST and a child path was denied. The issue is fixed in version 2.6.0. Defenders should verify OpenBao deployments, assess exposure, and prioritize upgrading to version 2.6.0 or later if using a version prior to 2.6.0, and assess exposure in their environment.
Defensive priority
Defenders should prioritize verifying and upgrading to OpenBao version 2.6.0 or later if using a version prior to 2.6.0, and assess exposure in their environment.
Recommended defensive actions
- Verify OpenBao version and upgrade to 2.6.0 or later if necessary
- Assess exposure in the environment
- Review and update ACL configurations
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- technicalSummary
Evidence notes
The CVE record and source references provide details on the issue, including its description, affected versions, and fixed version. OpenBao's vault/policy/acl.go could evaluate a broader wildcard ACL grant before more-specific trailing-wildcard ACL paths with capabilities = [deny] for a LIST operation. This issue allows listing a denied path if a parent path permitted LIST and a child path was denied. The issue is fixed in version 2.6.0. Defenders should verify OpenBao deployments, assess exposure, and prioritize upgrading to version
Sources and references
Verified primary and authoritative sources
-
CVE-2026-63131 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-63131
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-63131 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-63131
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/hashicorp/vault/blob/main/CHANGELOG.md
-
Source reference
Unverified legacy reference
URL: https://github.com/openbao/openbao/commit/2e9625d6cebe4639d051ef53dd6ce7c49914ae6a
-
Source reference
Unverified legacy reference
URL: https://github.com/openbao/openbao/commit/f58d848c139e5ba71aa63103fcfe101972b999fc
-
Source reference
Unverified legacy reference
URL: https://github.com/openbao/openbao/pull/3389
-
Source reference
Unverified legacy reference
URL: https://github.com/openbao/openbao/pull/3474
-
Source reference
Unverified legacy reference
URL: https://github.com/openbao/openbao/releases/tag/v2.6.0
-
Source reference
Unverified legacy reference
URL: https://github.com/openbao/openbao/security/advisories/GHSA-xp3c-3jw3-4vcr
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.