PT-2025-32379 · Openbao+1 · Openbao+1

Cipherboy

·

Published

2025-08-08

·

Updated

2025-09-12

·

CVE-2025-54996

CVSS v2.0

8.3

High

VectorAV:N/AC:L/Au:M/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions OpenBao versions 2.3.1 and below
Description OpenBao is a software solution for managing, storing, and distributing sensitive data. In affected versions, accounts with access to highly-privileged identity entity systems in root namespaces could increase their scope directly to the root policy. The identity system allowed adding arbitrary policies with capability grants on arbitrary paths, but the root policy was restricted to manual generation. The global root policy was not accessible from child namespaces.
Recommendations OpenBao versions prior to 2.3.2: Upgrade to version 2.3.2 or later to resolve this issue. As a temporary workaround, use of denied parameters in any policy which has access to the affected identity endpoints (on identity entities) may be sufficient to prohibit this type of attack.

Exploit

Fix

Improper Privilege Management

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

BDU:2025-11283
CVE-2025-54996
GHSA-VF84-MXRQ-CRQC
GO-2025-3857
OPENSUSE-SU-2025:15434-1
OPENSUSE-SU-2025:15460-1
SUSE-SU-2025:02912-1

Affected Products

Openbao
Red Os