Executive brief
OpenBao is an open-source system used for managing sensitive identities and secrets. A flaw in how the system handles the deletion of 'namespaces' (isolated environments) can result in sensitive data or active access leases remaining in storage even after the environment is marked as deleted. This could lead to unauthorized data retention or lingering access rights that should have been revoked, potentially impacting security compliance and data isolation.
Technical details
A vulnerability exists in OpenBao's namespace deletion logic where interrupted deletion processes (tainted namespaces) do not correctly clean up all associated data upon subsequent retry attempts. Specifically, the system may mark a namespace as deleted without successfully revoking all outstanding leases or removing unrelated storage entries. This occurs because mounts must be active for lease revocation to process correctly; if the initial deletion fails partway, subsequent attempts may bypass necessary cleanup steps. Attackers with low privileges could potentially exploit this to leave persistent data in the storage backend. The issue is addressed in version 2.5.3 by ensuring mounts are reloaded during deletion retries to facilitate proper lease revocation.
Affected products
- OpenBao OpenBao <= 2.5.2
Timeline
- 2026-04-20: patched: Fix committed and version 2.5.3 released.
- 2026-04-30: disclosed: Security advisory published on GitHub.
- 2026-05-14: advisory: CVE published to NVD.