Secrets Management Exposure in OpenBao by OpenBao
CVE-2026-46358
5.4MEDIUM
What is CVE-2026-46358?
OpenBao, an open-source identity-based secrets management system, has a vulnerability in its inline auth feature that fails to properly redact audit log entries, allowing sensitive authentication headers to be retained in cleartext. This flaw poses a security risk, as it may lead to unauthorized access to critical information, necessitating operators to evaluate and rotate any compromised authentication materials. The issue has been addressed in OpenBao version 2.5.4.
Affected Version(s)
openbao < 2.5.4
