{"schema_version":1,"title":"OpenBao vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 13 vulnerabilities in OpenBao: 3 in the last 7 days and 7 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-63132, was published on 23 September 2026.","url":"https://junglewise.ai/threats/technologies/openbao","json_url":"https://junglewise.ai/threats/technologies/openbao.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/openbao","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":3,"all_time":13,"critical":2,"exploited":0,"last_7_days":3,"last_30_days":7,"last_90_days":7,"last_365_days":13},"latest":[{"cve":"CVE-2026-63132","cvss":4,"epss":0.005,"slug":"cve-2026-63132-openbao-recovery-mode-timing-attack-token-leakage","title":"OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, OpenBao's handleLogicalRecovery path in http/logical.go","severity":"critical","exploited":false,"published_at":"2026-09-23T19:17:34.663+00:00","url":"https://junglewise.ai/threats/cve-2026-63132-openbao-recovery-mode-timing-attack-token-leakage"},{"cve":"CVE-2026-63131","cvss":4,"epss":0.0035,"slug":"cve-2026-63131-openbao-authorization-bypass-in-policy-enforcement-for-list","title":"OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, OpenBao's vault/policy/acl.go could evaluate a broader w","severity":"medium","exploited":false,"published_at":"2026-09-23T19:17:34.497+00:00","url":"https://junglewise.ai/threats/cve-2026-63131-openbao-authorization-bypass-in-policy-enforcement-for-list"},{"cve":"CVE-2026-71543","cvss":4,"epss":0.0042,"slug":"cve-2026-71543-openbao-templated-policies-privilege-escalation-via-wildcard","title":"OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, templated ACL, PKI, and SSH policies could substitute at","severity":"high","exploited":false,"published_at":"2026-09-21T15:17:31.173+00:00","url":"https://junglewise.ai/threats/cve-2026-71543-openbao-templated-policies-privilege-escalation-via-wildcard"},{"cve":"CVE-2026-55776","cvss":6.5,"epss":0.0061,"slug":"cve-2026-55776-openbao-denial-of-service-via-transit-engine-key-creation","title":"OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, an authenticated OpenBao caller with write access to tra","severity":"medium","exploited":false,"published_at":"2026-09-15T16:17:16.22+00:00","url":"https://junglewise.ai/threats/cve-2026-55776-openbao-denial-of-service-via-transit-engine-key-creation"},{"cve":"CVE-2026-55775","cvss":2.3,"epss":0.0048,"slug":"cve-2026-55775-openbao-improper-authorization-in-system-backend-namespace","title":"OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, OpenBao users granted capabilities on /sys/namespaces/ro","severity":"low","exploited":false,"published_at":"2026-09-15T16:17:16.073+00:00","url":"https://junglewise.ai/threats/cve-2026-55775-openbao-improper-authorization-in-system-backend-namespace"},{"cve":"CVE-2026-55774","cvss":2.1,"epss":0.0056,"slug":"cve-2026-55774-openbao-cross-namespace-lease-revocation-and-renewal-bypass","title":"OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, an OpenBao user with access to sys/leases/revoke/:lease_","severity":"low","exploited":false,"published_at":"2026-09-15T16:17:15.923+00:00","url":"https://junglewise.ai/threats/cve-2026-55774-openbao-cross-namespace-lease-revocation-and-renewal-bypass"},{"cve":"CVE-2026-55770","cvss":6.8,"epss":0.0053,"slug":"cve-2026-55770-openbao-ldap-injection-in-ldaputil-search-filter-construction","title":"OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, OpenBao used EscapeLDAPValue, an RFC 4514 distinguished","severity":"medium","exploited":false,"published_at":"2026-09-15T16:17:15.763+00:00","url":"https://junglewise.ai/threats/cve-2026-55770-openbao-ldap-injection-in-ldaputil-search-filter-construction"},{"cve":"CVE-2026-46405","cvss":5.3,"epss":0.0062,"slug":"cve-2026-46405-openbao-kerberos-auth-method-orphaned-token-accumulation","title":"OpenBao Kerberos auth method orphaned token accumulation","severity":"medium","exploited":false,"published_at":"2026-05-28T18:55:23+00:00","url":"https://junglewise.ai/threats/cve-2026-46405-openbao-kerberos-auth-method-orphaned-token-accumulation"},{"cve":"CVE-2026-46358","cvss":4,"epss":0.0021,"slug":"cve-2026-46358-openbao-sensitive-information-disclosure-in-audit-logs","title":"OpenBao sensitive information disclosure in audit logs","severity":"medium","exploited":false,"published_at":"2026-05-28T17:52:43+00:00","url":"https://junglewise.ai/threats/cve-2026-46358-openbao-sensitive-information-disclosure-in-audit-logs"},{"cve":"CVE-2026-45808","cvss":4,"epss":0.0043,"slug":"cve-2026-45808-openbao-authorization-bypass-in-sys-revoke-and-sys-renew","title":"OpenBao authorization bypass in sys/revoke and sys/renew endpoints","severity":"high","exploited":false,"published_at":"2026-05-28T17:37:32+00:00","url":"https://junglewise.ai/threats/cve-2026-45808-openbao-authorization-bypass-in-sys-revoke-and-sys-renew"},{"cve":"CVE-2026-42186","cvss":7.5,"epss":0.0043,"slug":"cve-2026-42186-openbao-improper-data-removal-during-namespace-deletion-retry","title":"OpenBao improper data removal during namespace deletion retry","severity":"high","exploited":false,"published_at":"2026-05-14T15:16:46.337+00:00","url":"https://junglewise.ai/threats/cve-2026-42186-openbao-improper-data-removal-during-namespace-deletion-retry"},{"cve":"CVE-2026-33758","cvss":6.1,"epss":0.0045,"slug":"cve-2026-33758-openbao-reflected-xss-in-oidc-authentication-callback","title":"OpenBao reflected XSS in OIDC authentication callback","severity":"medium","exploited":false,"published_at":"2026-03-27T15:16:57.863+00:00","url":"https://junglewise.ai/threats/cve-2026-33758-openbao-reflected-xss-in-oidc-authentication-callback"},{"cve":"CVE-2026-33757","cvss":9.6,"epss":0.0061,"slug":"cve-2026-33757-openbao-session-fixation-via-oidc-direct-callback-mode","title":"OpenBao session fixation via OIDC direct callback mode","severity":"critical","exploited":false,"published_at":"2026-03-27T15:16:57.69+00:00","url":"https://junglewise.ai/threats/cve-2026-33757-openbao-session-fixation-via-oidc-direct-callback-mode"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":4},{"week":"2026-09-21","critical":1,"exploited":0,"vulnerabilities":3}],"related":[],"technology":{"hub":true,"name":"OpenBao","slug":"openbao","vendor":{"name":"OpenBao","slug":"openbao","url":"https://junglewise.ai/threats/vendors/openbao"},"aliases":[],"category":"library","homepage":"https://openbao.org/","repo_url":"https://github.com/openbao/openbao","description":"OpenBao is an open-source community-driven project providing a software solution for managing secrets, certificates, and sensitive data.","url":"https://junglewise.ai/threats/technologies/openbao"},"most_severe":[{"cve":"CVE-2026-33757","cvss":9.6,"epss":0.0061,"slug":"cve-2026-33757-openbao-session-fixation-via-oidc-direct-callback-mode","title":"OpenBao session fixation via OIDC direct callback mode","severity":"critical","exploited":false,"published_at":"2026-03-27T15:16:57.69+00:00","url":"https://junglewise.ai/threats/cve-2026-33757-openbao-session-fixation-via-oidc-direct-callback-mode"},{"cve":"CVE-2026-63132","cvss":4,"epss":0.005,"slug":"cve-2026-63132-openbao-recovery-mode-timing-attack-token-leakage","title":"OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, OpenBao's handleLogicalRecovery path in http/logical.go","severity":"critical","exploited":false,"published_at":"2026-09-23T19:17:34.663+00:00","url":"https://junglewise.ai/threats/cve-2026-63132-openbao-recovery-mode-timing-attack-token-leakage"},{"cve":"CVE-2026-42186","cvss":7.5,"epss":0.0043,"slug":"cve-2026-42186-openbao-improper-data-removal-during-namespace-deletion-retry","title":"OpenBao improper data removal during namespace deletion retry","severity":"high","exploited":false,"published_at":"2026-05-14T15:16:46.337+00:00","url":"https://junglewise.ai/threats/cve-2026-42186-openbao-improper-data-removal-during-namespace-deletion-retry"},{"cve":"CVE-2026-45808","cvss":4,"epss":0.0043,"slug":"cve-2026-45808-openbao-authorization-bypass-in-sys-revoke-and-sys-renew","title":"OpenBao authorization bypass in sys/revoke and sys/renew endpoints","severity":"high","exploited":false,"published_at":"2026-05-28T17:37:32+00:00","url":"https://junglewise.ai/threats/cve-2026-45808-openbao-authorization-bypass-in-sys-revoke-and-sys-renew"},{"cve":"CVE-2026-71543","cvss":4,"epss":0.0042,"slug":"cve-2026-71543-openbao-templated-policies-privilege-escalation-via-wildcard","title":"OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, templated ACL, PKI, and SSH policies could substitute at","severity":"high","exploited":false,"published_at":"2026-09-21T15:17:31.173+00:00","url":"https://junglewise.ai/threats/cve-2026-71543-openbao-templated-policies-privilege-escalation-via-wildcard"},{"cve":"CVE-2026-55770","cvss":6.8,"epss":0.0053,"slug":"cve-2026-55770-openbao-ldap-injection-in-ldaputil-search-filter-construction","title":"OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, OpenBao used EscapeLDAPValue, an RFC 4514 distinguished","severity":"medium","exploited":false,"published_at":"2026-09-15T16:17:15.763+00:00","url":"https://junglewise.ai/threats/cve-2026-55770-openbao-ldap-injection-in-ldaputil-search-filter-construction"},{"cve":"CVE-2026-55776","cvss":6.5,"epss":0.0061,"slug":"cve-2026-55776-openbao-denial-of-service-via-transit-engine-key-creation","title":"OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, an authenticated OpenBao caller with write access to tra","severity":"medium","exploited":false,"published_at":"2026-09-15T16:17:16.22+00:00","url":"https://junglewise.ai/threats/cve-2026-55776-openbao-denial-of-service-via-transit-engine-key-creation"},{"cve":"CVE-2026-33758","cvss":6.1,"epss":0.0045,"slug":"cve-2026-33758-openbao-reflected-xss-in-oidc-authentication-callback","title":"OpenBao reflected XSS in OIDC authentication callback","severity":"medium","exploited":false,"published_at":"2026-03-27T15:16:57.863+00:00","url":"https://junglewise.ai/threats/cve-2026-33758-openbao-reflected-xss-in-oidc-authentication-callback"},{"cve":"CVE-2026-46405","cvss":5.3,"epss":0.0062,"slug":"cve-2026-46405-openbao-kerberos-auth-method-orphaned-token-accumulation","title":"OpenBao Kerberos auth method orphaned token accumulation","severity":"medium","exploited":false,"published_at":"2026-05-28T18:55:23+00:00","url":"https://junglewise.ai/threats/cve-2026-46405-openbao-kerberos-auth-method-orphaned-token-accumulation"},{"cve":"CVE-2026-63131","cvss":4,"epss":0.0035,"slug":"cve-2026-63131-openbao-authorization-bypass-in-policy-enforcement-for-list","title":"OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, OpenBao's vault/policy/acl.go could evaluate a broader w","severity":"medium","exploited":false,"published_at":"2026-09-23T19:17:34.497+00:00","url":"https://junglewise.ai/threats/cve-2026-63131-openbao-authorization-bypass-in-policy-enforcement-for-list"}],"generated_at":"2026-09-26T16:07:00.132667+00:00"}