OpenBao Identity-Based Secrets Management System Vulnerability
CVE-2026-46405

5.3MEDIUM

Key Information:

Vendor

Openbao

Status
Vendor
CVE Published:
7 August 2026

What is CVE-2026-46405?

In the OpenBao identity-based secrets management system, prior to version 2.5.4, a vulnerability exists within the Kerberos authentication method that exposes a logical.Auth object in responses when an Authorization: Negotiate header is supplied. This leads to the creation of authentication tokens with default policies and time-to-live values, without associated entity information. These tokens remain inaccessible to the requester and are not exposed outside the restricted sys/raw path. Users are advised to upgrade to version 2.5.4 to mitigate this risk or implement rate limiting to manage the creation of these paths effectively.

Affected Version(s)

openbao < 2.5.4

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.