PT-2026-65051 · Bitnami · Openbao
Published
2026-07-27
·
Updated
2026-07-27
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
OpenBao is an open source identity-based secrets management system. Prior to version 2.5.2, OpenBao installations that have an OIDC/JWT authentication method enabled and a role with
callback mode=direct configured are vulnerable to XSS via the error description parameter on the page for a failed authentication. This allows an attacker access to the token used in the Web UI by a victim. The error description parameter has been replaced with a static error message in v2.5.2. The vulnerability can be mitigated by removing any roles with callback mode set to direct. Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openbao