Executive brief
OpenBao is a security tool used to manage secrets and credentials across different isolated environments or 'namespaces'. A vulnerability in its legacy management interface allows a user in one environment to revoke or renew credentials belonging to a different environment if they obtain the relevant identifiers. This could lead to service disruptions or unauthorized credential extensions, undermining the security boundaries between different teams or tenants.
Technical details
An authorization bypass exists in OpenBao's legacy `sys/revoke` and `sys/renew` endpoints. While OpenBao uses namespaces to provide multi-tenant isolation, these undocumented legacy paths do not correctly enforce Access Control List (ACL) boundaries between namespaces. A remote attacker with low privileges who obtains a lease identifier from another tenant can trigger the revocation or renewal of that lease and its associated credentials. This vulnerability is classified as Incorrect Authorization (CWE-863) and is addressed in OpenBao version 2.5.4.
Affected products
- OpenBao OpenBao <= 2.5.3
Timeline
- 2026-05-21: disclosed
- 2026-05-28: advisory: GitHub Advisory published
- 2026-05-28: patched: Version 2.5.4 released