Identity-Based Secrets Management System Vulnerability in OpenBao
CVE-2026-55774
2.1LOW
What is CVE-2026-55774?
The vulnerability in OpenBao allows users with knowledge of lease identifiers to revoke leases across namespaces, undermining namespace ACL isolation. This flaw permits tenants to disrupt the access of other tenants by utilizing a known lease_id, effectively misusing the system's routing functions. This issue has been addressed in versions 2.5.5 and later, enhancing the security of the lease management system.
Affected Version(s)
openbao < 2.5.5
