Identity-Based Secrets Management Vulnerability in OpenBao
CVE-2026-71543
7.5HIGH
What is CVE-2026-71543?
OpenBao, an open-source identity-based secrets management system, has a significant vulnerability affecting versions before 2.6.0. This flaw allows attacker-controlled identity data to be injected into templated ACL, PKI, and SSH policies without proper validation, leading to potential privilege escalation and unauthorized access. Specific templated policies can be manipulated through characters like asterisks or commas, enabling broader certificate issuance and unauthorized domain access. To mitigate these risks, users of OpenBao should upgrade to version 2.6.0, where this vulnerability has been addressed.
Affected Version(s)
openbao <2.6.0
