PT-2026-42808 · Openbao · Openbao
Published
2026-05-21
·
Updated
2026-05-28
·
CVE-2026-46358
CVSS v4.0
5.4
Medium
| Vector | AV:L/AC:L/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenBao versions prior to 2.5.4
Description
The inline auth functionality incorrectly redacts audit log entries. This causes non-auth headers to be removed while auth-related headers are retained in cleartext. Exploitation requires an attacker to have compromised access to the audit device.
Recommendations
Update to version 2.5.4.
Review leaked source authentication material and rotate it as appropriate.
Fix
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openbao