Identity-Based Secrets Management Vulnerability in OpenBao by OpenBao
CVE-2026-55775
2.3LOW
What is CVE-2026-55775?
OpenBao, an open-source identity-based secrets management system, has a vulnerability that allows users with certain capabilities on /sys/namespaces/root within a non-root namespace to exploit improper handling of the root path. This vulnerability affects versions before 2.5.5, where ACL checks are bypassed due to root canonicalization resolving to an empty path. Consequently, this allows legitimate users to perform unauthorized operations like lookups, deletions, or changes to custom metadata directly in their containing namespace. The issue has been addressed in version 2.5.5 with fixes implemented to prevent such exploitation.
Affected Version(s)
openbao < 2.5.5
