Executive brief
OpenBao, an open-source security tool for managing secrets and sensitive data, contains a flaw in its audit logging system. The software incorrectly records authentication headers in cleartext while redacting non-sensitive information. If an attacker gains access to the audit logs, they could obtain credentials and compromise the security of the managed environment.
Technical details
A vulnerability in OpenBao's inline authentication functionality (CWE-532) leads to the improper redaction of sensitive information in audit logs. Specifically, the system removes non-authentication headers while retaining authentication-related headers in cleartext. Exploitation requires an attacker to have high privileges and local access to the audit device or log storage. If successful, an attacker can extract source authentication material from the logs. This issue is fixed in OpenBao version 2.5.4; operators are advised to rotate any potentially leaked credentials.
Affected products
- OpenBao OpenBao <= 2.5.3
Timeline
- 2026-05-21: disclosed
- 2026-05-28: advisory
- 2026-05-28: patched: Fixed in v2.5.4