CVE-2026-42186Low▾ SunlitOpenBao's Namespace Deletion May Not Delete Data Properly
▾ Sunlit zone — Low / medium · no exploitation signal
impact 13.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 27.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.2%
When OpenBao's initial namespace deletion fails, subsequent retries fail to properly remove all data before marking the namespace as deleted. This can affect any outstanding leases as well as potentially leaving unrelated storage entries around.
This will be patched in OpenBao v2.5.3.
Users may manually remove mounts prior to deleting the namespace.
Audit logs may be used to identify repeated deletion attempts against the same namespace; sys/raw can be used to see what leases were not correctly deleted.
github.com/openbao/openbao < 0.0.0-20260420173541-6d2e0506e2b4Upgrade to a patched release:
github.com/openbao/openbao 0.0.0-20260420173541-6d2e0506e2b4Connected by shared product, vendor, weakness, or advisory.
CVE-2026-39396Low· 3.1OpenBao: Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)
CVE-2026-40264LowOpenBao's Token Store Allows Cross-Namespace Renewal, Revocation
CVE-2026-39388Low· 3.1OpenBao's Certificate Authentication Allows Token Renewal With Different Certificate
CVE-2026-39946Medium· 4.9OpenBao's SQL Injection in PostgreSQL database secrets engine
CVE-2026-45808HighOpenBao is an open source identity-based secrets management system
CVE-2026-46358MediumOpenBao is an open source identity-based secrets management system