PatchSiren

openbao CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW openbao CVE published 2026-09-23

CVE-2026-77285

OpenBao Agent's exec rendering mode could write secrets from env_template to standard output after repeated rendering failures. This issue is fixed in version 2.6.0. The vulnerability arises when OpenBao Agent's exec rendering mode re-creates the template runner after repeated rendering failures, primarily after num_retries was reached. A process supervisor, log collector, or local user able to read that [truncated]

CRITICAL openbao CVE published 2026-09-23

CVE-2026-63132

A remote unauthenticated attacker could infer the highly privileged recovery token in OpenBao by making repeated recovery mode requests and measuring response timing. This issue is fixed in OpenBao version 2.6.0. The vulnerability allows attackers to access sensitive data and potentially modify OpenBao data. Defenders should assess exposure and prioritize upgrading to version 2.6.0 or later to mitigate th [truncated]

MEDIUM openbao CVE published 2026-09-23

CVE-2026-63131

OpenBao, an open-source identity-based secrets management system, had an issue where a broader wildcard ACL grant could be evaluated before more-specific trailing-wildcard ACL paths with capabilities = [deny] for a LIST operation. This could allow listing a denied path if a parent path permitted LIST and a child path was denied. The issue is fixed in version 2.6.0.

HIGH openbao CVE published 2026-09-21

CVE-2026-71543

OpenBao, an open-source identity-based secrets management system, had a vulnerability prior to version 2.6.0 where templated ACL, PKI, and SSH policies could substitute attacker-controlled identity data without rejecting syntax-significant characters. This could allow privilege escalation, unauthorized access, and unauthorized certificate issuance. The issue is fixed in version 2.6.0.

MEDIUM openbao CVE published 2026-09-15

CVE-2026-55776

CVE-2026-55776 is a denial-of-service vulnerability in OpenBao, an open-source identity-based secrets management system. An authenticated caller with write access to transit/keys/* could cause the server process to terminate by setting derived to true with specific asymmetric key types. This issue is fixed in version 2.5.5. The vulnerability arises from a double-unlock of a mutex in the error path of the [truncated]

LOW openbao CVE published 2026-09-15

CVE-2026-55775

OpenBao users with capabilities on /sys/namespaces/root within a non-root namespace could exploit special handling of the literal root path in namespace canonicalization. This allowed permitted lookups, deletion, locking, or custom metadata changes against the direct containing namespace. The issue is fixed in version 2.5.5. Affected deployments should verify and upgrade to prevent exploitation. Review ca [truncated]

LOW openbao CVE published 2026-09-15

CVE-2026-55774

OpenBao users with access to sys/leases/revoke/:lease_id in one namespace could revoke leases in another namespace if the foreign lease_id was known, bypassing namespace ACL isolation. This issue is fixed in version 2.5.5. The vulnerability allows unauthorized lease revocation across namespaces, potentially impacting OpenBao deployments with multiple namespaces. Administrators should verify access control [truncated]

MEDIUM openbao CVE published 2026-09-15

CVE-2026-55770

OpenBao, an open-source identity-based secrets management system, had a vulnerability prior to version 2.5.5. The system used EscapeLDAPValue, an RFC 4514 distinguished-name escaping function, where RFC 4515 LDAP search-filter escaping was required. This allowed an attacker-controlled username containing filter metacharacters to alter the search predicate and select a different directory entry. A resultin [truncated]

MEDIUM openbao CVE published 2026-08-07

CVE-2026-46405

OpenBao, an open-source identity-based secrets management system, had a vulnerability in its Kerberos auth method. When a GET handler was used or an Authorization: Negotiate header was supplied, the response included a logical.Auth object along with an error message. This resulted in tokens being created with default policy, TTL, and no entity information. These tokens were hidden by the returned error me [truncated]

HIGH openbao CVE published 2026-08-07

CVE-2026-45808

CVE-2026-45808 debrief based on the supplied source corpus. The CVE record was published on 2026-08-07T22:16:58.370Z. OpenBao's namespaces provide multi-tenant separation, but a tenant who intentionally leaks lease identifiers can have their lease and underlying credential revoked or renewed by a user in another tenant via the legacy, undocumented `sys/revoke` and `sys/renew` endpoints. This is fixed in O [truncated]

MEDIUM openbao CVE published 2026-08-07

CVE-2026-46358

OpenBao's inline auth functionality incorrectly redacted audit log entries, potentially leaking source authentication material. This issue requires access to the audit device and is fixed in OpenBao v2.5.4. Operators should review leaked source authentication material and rotate it as appropriate. The issue affects OpenBao instances, and administrators should assess their exposure and plan for upgrades or [truncated]

LOW openbao CVE published 2026-05-14

CVE-2026-42186

OpenBao versions prior to 2.5.3 contain a logic flaw in namespace deletion that can leave orphaned data when initial deletion attempts fail. The vulnerability stems from improper cleanup during retry operations, potentially affecting outstanding leases and leaving unrelated storage entries intact after a namespace is marked deleted. This represents a data integrity concern rather than direct confidentiali [truncated]

CRITICAL openbao CVE published 2026-03-27

CVE-2026-33758

OpenBao, an open-source identity-based secrets management system, has a critical vulnerability tracked as CVE-2026-33758. This vulnerability affects OpenBao installations with an OIDC/JWT authentication method enabled and a role configured with `callback_mode=direct`. The vulnerability allows an attacker to exploit the `error_description` parameter on the page for a failed authentication, potentially gain [truncated]

CRITICAL openbao CVE published 2026-03-27

CVE-2026-33757

CVE-2026-33757 is a critical authentication bypass vulnerability in OpenBao, an open-source identity-based secrets management system. The vulnerability allows an attacker to perform remote phishing by having a victim visit a URL and automatically log in to the attacker's session. This is possible because OpenBao does not prompt for user confirmation when logging in via JWT/OIDC and a role with `callback_m [truncated]