PT-2026-37251 · Go+1 · Github.Com/Openbao/Openbao+1

Cipherboy

·

Published

2026-05-05

·

Updated

2026-05-14

·

CVE-2026-42186

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenBao versions prior to 2.5.3
Description An issue exists in the identity-based secrets management system where an initial failure during namespace deletion causes subsequent retries to fail to remove all data before the namespace is marked as deleted. This may result in outstanding leases remaining active or unrelated storage entries being left behind.
Recommendations Update to version 2.5.3. Manually remove mounts prior to deleting the namespace. Use audit logs to identify repeated deletion attempts against the same namespace and utilize sys/raw to identify leases that were not correctly deleted.

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-42186
GHSA-VV66-6RP4-WR4F

Affected Products

Github.Com/Openbao/Openbao
Openbao