CVE-2026-63132
- EPSS 0.5%
- Veröffentlicht 23.09.2026 17:59:19
- Zuletzt bearbeitet 29.09.2026 19:06:32
OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, OpenBao's handleLogicalRecovery path in http/logical.go compared the highly privileged recovery token with ordinary string equality. A remote unauthenticated attacker...
- EPSS 0.35%
- Veröffentlicht 23.09.2026 17:59:16
- Zuletzt bearbeitet 29.09.2026 19:06:32
OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, OpenBao's vault/policy/acl.go could evaluate a broader wildcard ACL grant before more-specific trailing-wildcard ACL paths with capabilities = ["deny"] for a LIST ope...
CVE-2026-77285
- EPSS 0.13%
- Veröffentlicht 23.09.2026 17:59:13
- Zuletzt bearbeitet 29.09.2026 19:06:32
OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, OpenBao Agent's exec rendering mode could write secrets from env_template to standard output when command/agent/exec/exec.go re-created the template runner after repe...
CVE-2026-71543
- EPSS 0.25%
- Veröffentlicht 21.09.2026 15:17:31
- Zuletzt bearbeitet 25.09.2026 20:17:46
OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, templated ACL, PKI, and SSH policies could substitute attacker-controlled identity data without rejecting syntax-significant characters. In ACL templated policies, as...
CVE-2026-55770
- EPSS 0.45%
- Veröffentlicht 15.09.2026 15:44:35
- Zuletzt bearbeitet 29.09.2026 19:06:32
OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, OpenBao used EscapeLDAPValue, an RFC 4514 distinguished-name escaping function, where RFC 4515 LDAP search-filter escaping was required in sdk/helper/ldaputil/client....
CVE-2026-55776
- EPSS 0.46%
- Veröffentlicht 15.09.2026 15:43:29
- Zuletzt bearbeitet 29.09.2026 19:06:32
OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, an authenticated OpenBao caller with write access to transit/keys/* could terminate the server process by setting derived to true while the type parameter selected rs...
CVE-2026-55774
- EPSS 0.44%
- Veröffentlicht 15.09.2026 15:42:03
- Zuletzt bearbeitet 25.09.2026 14:23:59
OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, an OpenBao user with access to sys/leases/revoke/:lease_id in one namespace could revoke a lease in another namespace when the foreign lease_id was known, bypassing n...
CVE-2026-55775
- EPSS 0.36%
- Veröffentlicht 15.09.2026 15:40:32
- Zuletzt bearbeitet 25.09.2026 14:23:59
OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, OpenBao users granted capabilities on /sys/namespaces/root within a non-root namespace could exploit special handling of the literal root path in namespace canonicali...
CVE-2026-45808
- EPSS 0.31%
- Veröffentlicht 07.08.2026 21:15:00
- Zuletzt bearbeitet 09.09.2026 21:02:22
OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's namespaces provide multi-tenant separation. A tenant who intentionally leaks lease identifiers can have their lease and underlying credential revoke...
CVE-2026-46405
- EPSS 0.36%
- Veröffentlicht 07.08.2026 21:14:35
- Zuletzt bearbeitet 09.09.2026 21:02:22
OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, in OpenBao's Kerberos auth method on the `GET` handler, or when an `Authorization: Negotiate` header is supplied, the response is includes a `logical.Auth` ob...