Unauthenticated Operation Vulnerability in OpenBao Data Management Software
CVE-2025-52894

6.9MEDIUM

Key Information:

Vendor

Openbao

Status
Vendor
CVE Published:
25 June 2025

What is CVE-2025-52894?

OpenBao is a software solution used for managing, storing, and distributing sensitive data, including secrets, certificates, and keys. Prior to version 2.2.2, OpenBao allowed attackers to execute unauthenticated and unaudited cancellation of root rekey and recovery rekey operations, potentially leading to a denial of service. To mitigate this risk in version 2.2.2 and onward, operators can set the configuration option disable_unauthed_rekey_endpoints=true, thus disabling the vulnerable endpoints globally. Future releases of OpenBao will ensure that this setting is enabled by default for all users and will offer an authenticated alternative. Additionally, deploying a proxy or load balancer can help restrict access to these endpoints from unauthorized IP ranges, enhancing overall security.

Affected Version(s)

openbao < 2.2.2

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-52894 : Unauthenticated Operation Vulnerability in OpenBao Data Management Software