Identity-Based Secrets Management Vulnerability in OpenBao by OpenBao
CVE-2026-55775

2.3LOW

Key Information:

Vendor

Openbao

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-55775?

OpenBao, an open-source identity-based secrets management system, has a vulnerability that allows users with certain capabilities on /sys/namespaces/root within a non-root namespace to exploit improper handling of the root path. This vulnerability affects versions before 2.5.5, where ACL checks are bypassed due to root canonicalization resolving to an empty path. Consequently, this allows legitimate users to perform unauthorized operations like lookups, deletions, or changes to custom metadata directly in their containing namespace. The issue has been addressed in version 2.5.5 with fixes implemented to prevent such exploitation.

Affected Version(s)

openbao < 2.5.5

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.