Junglewise Threat Intelligence

CVE-2026-46358: OpenBao sensitive information disclosure in audit logs

CVE-2026-46358 · Severity: medium · CVSS 4 · Published 2026-05-28

Technologies: github.com/openbao/openbao (Go), OpenBao. Vendors: Go, OpenBao.

Executive brief

OpenBao, an open-source security tool for managing secrets and sensitive data, contains a flaw in its audit logging system. The software incorrectly records authentication headers in cleartext while redacting non-sensitive information. If an attacker gains access to the audit logs, they could obtain credentials and compromise the security of the managed environment.

Technical details

A vulnerability in OpenBao's inline authentication functionality (CWE-532) leads to the improper redaction of sensitive information in audit logs. Specifically, the system removes non-authentication headers while retaining authentication-related headers in cleartext. Exploitation requires an attacker to have high privileges and local access to the audit device or log storage. If successful, an attacker can extract source authentication material from the logs. This issue is fixed in OpenBao version 2.5.4; operators are advised to rotate any potentially leaked credentials.

Affected products

  • OpenBao OpenBao <= 2.5.3

Timeline

  • 2026-05-21: disclosed
  • 2026-05-28: advisory
  • 2026-05-28: patched: Fixed in v2.5.4

References

Related threats