PT-2026-28530 · Openbao+1 · Openbao+1
Gianklug
·
Published
2026-03-26
·
Updated
2026-05-29
·
CVE-2026-33758
CVSS v4.0
9.4
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
OpenBao versions prior to 2.5.2
Description
OpenBao, an open source identity-based secrets management system, is susceptible to Reflected Cross-Site Scripting (XSS) through the
error description parameter during failed authentication attempts when an OIDC/JWT authentication method is enabled and a role is configured with callback mode=direct. This allows an attacker to gain access to the token used in the Web UI by a victim. The issue is addressed by replacing the error description parameter with a static error message. The API endpoint involved in the vulnerability is not explicitly mentioned. The vulnerable parameter is error description.Recommendations
Versions prior to 2.5.2 should be updated to version 2.5.2 or later.
As a mitigation, remove any roles with
callback mode set to direct.Exploit
Fix
XSS
Improper Encoding or Escaping of Output
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openbao
Red Os