Identity-Based Secrets Management Vulnerability in OpenBao
CVE-2026-71543

7.5HIGH

Key Information:

Vendor

Openbao

Status
Vendor
CVE Published:
21 September 2026

What is CVE-2026-71543?

OpenBao, an open-source identity-based secrets management system, has a significant vulnerability affecting versions before 2.6.0. This flaw allows attacker-controlled identity data to be injected into templated ACL, PKI, and SSH policies without proper validation, leading to potential privilege escalation and unauthorized access. Specific templated policies can be manipulated through characters like asterisks or commas, enabling broader certificate issuance and unauthorized domain access. To mitigate these risks, users of OpenBao should upgrade to version 2.6.0, where this vulnerability has been addressed.

Affected Version(s)

openbao <2.6.0

References

CVSS V4

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.