Vulnerability in OpenBao's Secrets Management System Affects LDAP Authentication
CVE-2026-55770

6.8MEDIUM

Key Information:

Vendor

Openbao

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-55770?

OpenBao, an open-source identity-based secrets management system, prior to version 2.5.5, has a vulnerability in its LDAP authentication mechanism. The issue arises from the incorrect handling of LDAP filter metacharacters in user inputs, which can lead to unauthorized access. Specifically, the use of the EscapeLDAPValue function allows attacker-controlled usernames to manipulate search predicates, potentially providing access to secrets or sensitive capabilities associated with other LDAP identities. The vulnerability is mitigated in version 2.5.5, which requires users to update to this version to secure their installations.

Affected Version(s)

openbao < 2.5.5

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.