PT-2026-42807 · Openbao · Openbao

Published

2026-05-21

·

Updated

2026-05-29

·

CVE-2026-45808

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenBao versions prior to 2.5.4
Description Namespaces in OpenBao are designed to provide multi-tenant separation. However, a tenant that leaks lease identifiers may allow a user from another tenant to revoke or renew their lease and underlying credentials. This occurs through the legacy, undocumented endpoints "sys/revoke" and "sys/renew".
Recommendations Update to version 2.5.4.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-45808
GHSA-V8V8-CM84-M686
OPENSUSE-SU-2026:10835-1

Affected Products

Openbao