CVE-2025-55001Medium· 6.5▾ SunlitOpenBao LDAP MFA Enforcement Bypass When Using Username As Alias
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 27.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.2%
OpenBao allows assignment of policies and MFA attribution based upon entity aliases, chosen by the underlying auth method. When using the username_as_alias=true parameter in the LDAP auth method, the caller-supplied username is used verbatim without normalization, allowing an attacker to bypass alias-specific MFA requirements.
OpenBao v2.3.2 will patch this issue.
LDAP methods are only vulnerable if using username_as_alias=true. Remove all usage of this parameter and update any entity aliases accordingly.
This issue was disclosed to HashiCorp and is the OpenBao equivalent of the following tickets:
github.com/openbao/openbao >= 0.1.0, < 2.3.2github.com/openbao/openbao < 0.0.0-20250807212521-c52795c1ef74Upgrade to a patched release:
github.com/openbao/openbao 2.3.2github.com/openbao/openbao 0.0.0-20250807212521-c52795c1ef74Connected by shared product, vendor, weakness, or advisory.
CVE-2025-54998Medium· 5.3OpenBao Userpass and LDAP User Lockout Bypass
CVE-2026-45808HighOpenBao is an open source identity-based secrets management system
CVE-2026-46358MediumOpenBao is an open source identity-based secrets management system
CVE-2026-46405Medium· 5.3OpenBao is an open source identity-based secrets management system
CVE-2025-54997Critical· 9.1Privileged OpenBao Operator May Execute Code on the Underlying Host
CVE-2026-42186LowOpenBao's Namespace Deletion May Not Delete Data Properly