PT-2025-47976 · Openbao+1 · Openbao+1
Published
2025-11-24
·
Updated
2026-03-19
·
CVE-2025-64761
CVSS v4.0
7.5
High
| Vector | AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenBao versions prior to 2.4.4
Description
OpenBao is an identity-based secrets management system. A privileged operator could leverage the identity group subsystem to add a root policy to a group identity group, potentially escalating their own or another user's permissions. This occurs when an operator in the root namespace has access to identity/groups endpoints and lacks policy access. An operator with policy access could also create or modify a policy to grant root-equivalent permissions using the sudo capability. The issue involves the
/identity/groups API endpoint.Recommendations
Update to version 2.4.4 or later.
Exploit
Fix
LPE
Incorrect Privilege Assignment
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openbao
Red Os