Identity-Based Secrets Management System Vulnerability in OpenBao
CVE-2026-55774

2.1LOW

Key Information:

Vendor

Openbao

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-55774?

The vulnerability in OpenBao allows users with knowledge of lease identifiers to revoke leases across namespaces, undermining namespace ACL isolation. This flaw permits tenants to disrupt the access of other tenants by utilizing a known lease_id, effectively misusing the system's routing functions. This issue has been addressed in versions 2.5.5 and later, enhancing the security of the lease management system.

Affected Version(s)

openbao < 2.5.5

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.