2.3
CVE-2026-55775
- EPSS 0.36%
- Veröffentlicht 15.09.2026 15:40:32
- Zuletzt bearbeitet 25.09.2026 14:23:59
- Erkennungen
OpenBao's System Backend allows Unauthorized Management of the containing Namespace
OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, OpenBao users granted capabilities on /sys/namespaces/root within a non-root namespace could exploit special handling of the literal root path in namespace canonicalization. The /sys/namespaces/* endpoint family can resolve its containing namespace through a path prefix or X-Vault-Namespace header. ACL checks occurred before root canonicalized to an empty path, causing /sys/namespaces/root to resolve to the system backend's containing namespace and allowing permitted lookups, deletion, locking, or custom metadata changes against that direct containing namespace. The root namespace and arbitrary unrelated namespaces are not affected, and available operations depend on the capabilities granted on the path and subpaths such as /api-lock. This issue is fixed in version 2.5.5.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstelleropenbao
≫
Produkt
openbao
Version
< 2.5.5
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.36% | 0.295 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 2.3 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-285 Improper Authorization
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
https://github.com/openbao/openbao/releases/tag/v2.5.5
https://github.com/openbao/openbao/releases/tag/v2.6.0
https://github.com/openbao/openbao/security/advisories/GHSA-mwr2-wmgp-crj6
https://github.com/openbao/openbao/pull/3308
https://github.com/openbao/openbao/pull/3311
https://github.com/openbao/openbao/commit/216b623cdde161eb7798bd095fc874c2174a4dd2
https://github.com/openbao/openbao/commit/d3c1cc64b1ae7f9868b5c3e80b8b11671f0d97ae