---
id: CVE-2026-63132
title: OpenBao is an open source identity-based secrets management system
summary: >-
  OpenBao is an open source identity-based secrets management system. Prior to
  2.6.0, OpenBao's handleLogicalRecovery path in http/logical.go compared the
  highly privileged recovery token with ordinary string equality. A remote
  unauthentic…
severity: critical
cvss: 9.2
cvssVector: 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'
cwe:
  - CWE-208
vendor: openbao
product: openbao
affected:
  - openbao < 2.6.0
patched:
  - github.com/openbao/openbao 0.0.0-20260713141742-763625a20721
published: '2026-09-23'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T20:17:12.490'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-63132'
references:
  - url: 'https://github.com/hashicorp/vault/blob/main/CHANGELOG.md#203'
    label: security-advisories@github.com
  - url: >-
      https://github.com/openbao/openbao/commit/0f2d90c331f25d1c6cd108638da03f4c7bd949a8
    label: security-advisories@github.com
  - url: >-
      https://github.com/openbao/openbao/commit/763625a2072103ea9e9122f2a8408e0b988d287a
    label: security-advisories@github.com
  - url: 'https://github.com/openbao/openbao/pull/3388'
    label: security-advisories@github.com
  - url: 'https://github.com/openbao/openbao/pull/3472'
    label: security-advisories@github.com
  - url: 'https://github.com/openbao/openbao/releases/tag/v2.6.0'
    label: security-advisories@github.com
  - url: 'https://github.com/openbao/openbao/security/advisories/GHSA-34fc-gh42-pj53'
    label: security-advisories@github.com
  - url: 'https://github.com/advisories/GHSA-34fc-gh42-pj53'
  - url: 'https://github.com/openbao/openbao'
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-63132.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-63132'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2539618'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-63132'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-63132'
tags:
  - nvd
  - cve.org
  - ghsa
  - go
  - osv
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-23T19:13:35.308605Z'
cvssSource: cna
aliases:
  - GHSA-34fc-gh42-pj53
ecosystem: go
ingestedAt: '2026-09-22T21:11:40.317Z'
scores:
  cna: 9.2
  vendor: 7.4
epss: 0.00497
epssPercentile: 0.39942
---

## Overview

OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, OpenBao's handleLogicalRecovery path in http/logical.go compared the highly privileged recovery token with ordinary string equality. A remote unauthenticated attacker able to make repeated recovery mode requests and measure response timing could infer the recovery token. The recovered token could then authorize recovery mode operations that read or modify OpenBao data. This issue is fixed in version 2.6.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-63132)

Affected packages:

- `github.com/openbao/openbao < 0.0.0-20260713141742-763625a20721`
- `github.com/openbao/openbao >= 0.1.0, <= 1.1.5`

Patched in:

- `github.com/openbao/openbao 0.0.0-20260713141742-763625a20721`

Source: https://github.com/advisories/GHSA-34fc-gh42-pj53

## Vendor advisories

- **Red Hat VEX** · Important · affected: Cryostat 4, Red Hat Hardened Images, Red Hat OpenShift GitOps · no fix planned: Red Hat Hardened Images, Cryostat 4, Red Hat OpenShift GitOps · updated 2026-09-25 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-63132.json)
