CVEs we hold for Openbao
Records whose assigning authority named Openbao as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-55776OpenBao: Transit secrets engine crashes on key creation with `derived: true` for asymmetric key typesopenbao CVE-2026-55775OpenBao's System Backend allows Unauthorized Management of the containing Namespaceopenbao CVE-2026-55774OpenBao: Cross-namespace lease revocation/renewal via canonical sys/leases/{revoke,renew} — incomplete fix of…openbao CVE-2026-46405OpenBao's Kerberos Auth Method Accumulates Unaccessible Tokensopenbao CVE-2026-46358OpenBao's Inline Auth Incorrectly Redacted Headersopenbao CVE-2026-45808OpenBao's cross-namespace lease revocation via legacy sys/revoke path bypasses ACLopenbao CVE-2026-42186OpenBao's Namespace Deletion May Not Delete Data Properlyopenbao CVE-2026-40264OpenBao's Token Store Allows Cross-Namespace Renewal, Revocationopenbao CVE-2026-39946OpenBao allows SQL Injection in PostgreSQL database secrets engineopenbao CVE-2026-39396OpenBao has Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)openbao CVE-2026-39388OpenBao's Certificate Authentication Allows Token Renewal With Different Certificateopenbao CVE-2026-33758OpenBao has Reflected XSS in its OIDC authentication error messageopenbao CVE-2026-33757OpenBao lacks user confirmation for OIDC direct callback modeopenbao CVE-2025-64761OpenBao Privileged Operator Identity Group Root Escalationopenbao CVE-2025-62705OpenBao and Vault Leak []byte Fields in Audit Logsopenbao CVE-2025-59048OpenBao AWS Plugin Vulnerable to Cross-Account IAM Role Impersonation in AWS Auth Methodopenbao-plugins CVE-2025-59043OpenBao vulnerable to denial of service via malicious JSON request processingopenbao CVE-2025-55003OpenBao Login MFA Bypasses Rate Limiting and TOTP Token Reuseopenbao CVE-2025-55001OpenBao LDAP MFA Enforcement Bypass When Using Username As Aliasopenbao CVE-2025-54999OpenBao: Timing Side-Channel in Userpass Auth Methodopenbao CVE-2025-54997OpenBao: Privileged Operator May Execute Code on the Underlying Hostopenbao CVE-2025-54996OpenBao Root Namespace Operator May Elevate Token Privilegesopenbao CVE-2025-52894OpenBao Vulnerable to Unauthenticated Rekey Operation Cancellationopenbao CVE-2025-52893OpenBao May Leak Sensitive Information in Logs When Processing Malformed Dataopenbao 28 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.