CVE-2025-54996High· 7.2▾ TwilightOpenBao Root Namespace Operator May Elevate Token Privileges
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.6 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 27.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.3%
Accounts with access to the highly-privileged identity entity system in the root namespace may increase their scope directly to the root policy. While the identity system always allowed adding arbitrary policies, which in turn could contain capability grants on arbitrary paths, the root policy is restricted to manual generation using unseal or recovery key shares. The global root policy is not accessible from child namespaces.
OpenBao v2.3.2 will patch this issue.
Use of denied_parameters in any policy which has access to the affected identity endpoints (on identity entities) may be sufficient to prohibit this type of attack.
This issue was disclosed to HashiCorp and is the OpenBao equivalent of the following tickets:
github.com/openbao/openbao >= 0.1.0, < 2.3.2github.com/openbao/openbao < 0.0.0-20250806193240-9b0b5d4f345fUpgrade to a patched release:
github.com/openbao/openbao 2.3.2github.com/openbao/openbao 0.0.0-20250806193240-9b0b5d4f345fConnected by shared product, vendor, weakness, or advisory.
CVE-2025-54997Critical· 9.1Privileged OpenBao Operator May Execute Code on the Underlying Host
CVE-2026-71543High· 7.2OpenBao is an open source identity-based secrets management system
CVE-2026-45808HighOpenBao is an open source identity-based secrets management system
CVE-2026-46358MediumOpenBao is an open source identity-based secrets management system
CVE-2026-46405Medium· 5.3OpenBao is an open source identity-based secrets management system
CVE-2026-42186LowOpenBao's Namespace Deletion May Not Delete Data Properly