PT-2025-47976 · Openbao+1 · Openbao+1

Publicado

2025-11-24

·

Atualizado

2026-03-19

·

CVE-2025-64761

CVSS v4.0

7.5

Alta

VetorAV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenBao versions prior to 2.4.4
Description OpenBao is an identity-based secrets management system. A privileged operator could leverage the identity group subsystem to add a root policy to a group identity group, potentially escalating their own or another user's permissions. This occurs when an operator in the root namespace has access to identity/groups endpoints and lacks policy access. An operator with policy access could also create or modify a policy to grant root-equivalent permissions using the sudo capability. The issue involves the /identity/groups API endpoint.
Recommendations Update to version 2.4.4 or later.

Exploit

Correção

LPE

Incorrect Privilege Assignment

Improper Privilege Management

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-64761
GHSA-7FF4-JW48-3436
GO-2025-4156
OPENSUSE-SU-2025:15767-1
SUSE-SU-2025:4395-1

Produtos afetados

Openbao
Red Os