Skip to main content

Vendor archive

openbao CVEs

Beta · best-effort

26 CVEs tagged to vendor openbao3 Critical, 8 High, 10 Medium, 5 Low, 0 Unrated.

CVE-2026-42186

Published May 14, 2026

OpenBao is an open source identity-based secrets management system. Prior to 2.5.3, when OpenBao's initial namespace deletion fails, subsequent retries fail to properly remove all…

CVSS 2.3 · Low
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-40264

Published Apr 21, 2026

OpenBao is an open source identity-based secrets management system. OpenBao's namespaces provide multi-tenant separation. Prior to version 2.5.3, a tenant who leaks token accessor…

CVSS 2.0 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-39946

Published Apr 21, 2026

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, when OpenBao revoked privileges on a role in the PostgreSQL database secrets engine, Op…

CVSS 4.6 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-39396

Published Apr 21, 2026

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, `ExtractPluginFromImage()` in OpenBao's OCI plugin downloader extracts a plugin binary…

CVSS 3.1 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-39388

Published Apr 21, 2026

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, OpenBao's Certificate authentication method, when a token renewal is requested and `dis…

CVSS 2.0 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-33758

Published Mar 27, 2026

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.2, OpenBao installations that have an OIDC/JWT authentication method enabled and a role wi…

CVSS 9.4 · Critical
evidence mentions
7
Buzz score
33.8
Vendor/product tagsBeta · best-effort

CVE-2026-33757

Published Mar 27, 2026

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.2, OpenBao does not prompt for user confirmation when logging in via JWT/OIDC and a role w…

CVSS 9.6 · Critical
evidence mentions
6
Buzz score
34.0
Vendor/product tagsBeta · best-effort

CVE-2025-64761

Published Nov 25, 2025

OpenBao is an open source identity-based secrets management system. Prior to version 2.4.4, a privileged operator could use the identity group subsystem to add a root policy to a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-59048

Published Oct 23, 2025

OpenBao's AWS Plugin generates AWS access credentials based on IAM policies. Prior to version 0.1.1, the AWS Plugin is vulnerable to cross-account IAM role Impersonation in the AW…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-62705

Published Oct 22, 2025

OpenBao is an open source identity-based secrets management system. Prior to version 2.4.2, OpenBao's audit log did not appropriately redact fields when relevant subsystems sent […

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-62513

Published Oct 22, 2025

OpenBao is an open source identity-based secrets management system. In versions 2.2.0 to 2.4.1, OpenBao's audit log experienced a regression wherein raw HTTP bodies used by few en…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-59043

Published Oct 17, 2025

OpenBao is an open source identity-based secrets management system. In OpenBao versions prior to 2.4.1, JSON objects after decoding may use significantly more memory than their se…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-55003

Published Aug 9, 2025

OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 2.3.1 and below, OpenBao's Log…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-55001

Published Aug 9, 2025

OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 2.3.1 and below, OpenBao allow…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-55000

Published Aug 9, 2025

OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 0.1.0 through 2.3.1, OpenBao's…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-54999

Published Aug 9, 2025

OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 0.1.0 through 2.3.1, when usin…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-54998

Published Aug 9, 2025

OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 0.1.0 through 2.3.1, attackers…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-54997

Published Aug 9, 2025

OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 2.3.1 and below, some OpenBao…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-54996

Published Aug 9, 2025

OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 2.3.1 and below, accounts with…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2025-52894

Published Jun 25, 2025

OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. OpenBao before v2.3.0 allowed an attacker…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-52893

Published Jun 25, 2025

OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. OpenBao before v2.3.0 may leak sensitive i…

CVSS 4.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-4166

Published May 2, 2025

Vault Community and Vault Enterprise Key/Value (kv) Version 2 plugin may unintentionally expose sensitive information in server and audit logs when users submit malformed payloads…

CVSS 4.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-8185

Published Oct 31, 2024

Vault Community and Vault Enterprise (“Vault”) clusters using Vault’s Integrated Storage backend are vulnerable to a denial-of-service (DoS) attack through memory exhaustion throu…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-9180

Published Oct 10, 2024

A privileged Vault operator with write permissions to the root namespace’s identity endpoint could escalate their own or another user’s privileges to Vault’s root policy. Fixed in…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-7594

Published Sep 26, 2024

Vault’s SSH secrets engine did not require the valid_principals list to contain a value by default. If the valid_principals and default_user fields of the SSH secrets engine confi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 26 CVEsPage 1 of 2