Secrets Management Exposure in OpenBao by OpenBao
CVE-2026-46358

5.4MEDIUM

Key Information:

Vendor

Openbao

Status
Vendor
CVE Published:
7 August 2026

What is CVE-2026-46358?

OpenBao, an open-source identity-based secrets management system, has a vulnerability in its inline auth feature that fails to properly redact audit log entries, allowing sensitive authentication headers to be retained in cleartext. This flaw poses a security risk, as it may lead to unauthorized access to critical information, necessitating operators to evaluate and rotate any compromised authentication materials. The issue has been addressed in OpenBao version 2.5.4.

Affected Version(s)

openbao < 2.5.4

References

CVSS V4

Score:
5.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.