OpenBao Identity-Based Secrets Management System Vulnerability
CVE-2026-46405
5.3MEDIUM
What is CVE-2026-46405?
In the OpenBao identity-based secrets management system, prior to version 2.5.4, a vulnerability exists within the Kerberos authentication method that exposes a logical.Auth object in responses when an Authorization: Negotiate header is supplied. This leads to the creation of authentication tokens with default policies and time-to-live values, without associated entity information. These tokens remain inaccessible to the requester and are not exposed outside the restricted sys/raw path. Users are advised to upgrade to version 2.5.4 to mitigate this risk or implement rate limiting to manage the creation of these paths effectively.
Affected Version(s)
openbao < 2.5.4
