CVE-2026-63131Medium▾ SunlitOpenBao Skips Stricter Deny Policy for LIST operations
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
When a policy operator has written capabilities = ["deny"] on a path with a trailing wildcard but allowed a broader list operation (e.g., a deny on secrets/metadata/restricted/* but allowed list on secrets/metadata/*), OpenBao would incorrectly allow the operation. This did not impact other operation types.
This has been patched in OpenBao v2.6.0.
github.com/openbao/openbao < 0.0.0-20260713133043-f58d848c139egithub.com/openbao/openbao >= 0.1.0, <= 1.1.5Upgrade to a patched release:
github.com/openbao/openbao 0.0.0-20260713133043-f58d848c139eConnected by shared product, vendor, weakness, or advisory.
CVE-2026-63132CriticalOpenBao's Recovery Mode Vulnerable To Token Leakage via Timing Attack
CVE-2026-71543HighOpenBao is an open source identity-based secrets management system
CVE-2026-77285LowOpenBao Agent Writes Secrets to Stdout
CVE-2026-45808HighOpenBao is an open source identity-based secrets management system
CVE-2026-55774Low· 2.1OpenBao is an open source identity-based secrets management system
CVE-2026-46358MediumOpenBao is an open source identity-based secrets management system