CVE-2026-39946Medium· 4.9▾ SunlitOpenBao's SQL Injection in PostgreSQL database secrets engine
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 27.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
0.2%
Last analysed / modified upstream
When OpenBao revoked privileges on a role in the PostgreSQL database secrets engine, OpenBao failed to use proper database quoting on schema names provided by PostgreSQL. This could lead to role revocation failures, or more rarely, SQL injection as the management user.
This vulnerability was originally from HashiCorp Vault.
This was addressed in v2.5.3.
Audit table schemas and ensure database users cannot create new schemas and grant privileges on them.
github.com/openbao/openbao < 0.0.0-20260420155735-b596b0882620Upgrade to a patched release:
github.com/openbao/openbao 0.0.0-20260420155735-b596b0882620Connected by shared product, vendor, weakness, or advisory.
CVE-2026-42186LowOpenBao's Namespace Deletion May Not Delete Data Properly
CVE-2026-39396Low· 3.1OpenBao: Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)
CVE-2026-40264LowOpenBao's Token Store Allows Cross-Namespace Renewal, Revocation
CVE-2026-39388Low· 3.1OpenBao's Certificate Authentication Allows Token Renewal With Different Certificate
CVE-2026-45808HighOpenBao is an open source identity-based secrets management system
CVE-2026-46358MediumOpenBao is an open source identity-based secrets management system