Junglewise Threat Intelligence

CVE-2026-40264: OpenBao's Token Store Allows Cross-Namespace Renewal, Revocation

CVE-2026-40264 · Severity: medium · CVSS 4 · Published 2026-04-21

Technologies: github.com/openbao/openbao (Go). Vendors: Go.

Executive brief

### Impact

OpenBao's namespaces provide multi-tenant separation. A tenant who leaks token accessors can have their token revoked or renewed by a privileged administrator in another tenant.

### Patches

This was addressed in v2.5.3.

Affected products

  • Go github.com/openbao/openbao

References

Related threats