CVE-2026-77285Low▾ SunlitOpenBao Agent Writes Secrets to Stdout
▾ Sunlit zone — Low / medium · no exploitation signal
impact 13.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
During certain error conditions, OpenBao Agent's exec rendering mode will incorrectly write secrets specified in env_template to stdout. This primarily happens when num_retries is met.
This vulnerability is original to Vault and was reported via the OpenBao security mailing list.
This is addressed in OpenBao v2.6.0 GA.
github.com/openbao/openbao < 0.0.0-20260714163218-90272575e5f5github.com/openbao/openbao >= 0.1.0, <= 1.1.5Upgrade to a patched release:
github.com/openbao/openbao 0.0.0-20260714163218-90272575e5f5Connected by shared product, vendor, weakness, or advisory.
CVE-2026-63132CriticalOpenBao's Recovery Mode Vulnerable To Token Leakage via Timing Attack
CVE-2026-63131MediumOpenBao Skips Stricter Deny Policy for LIST operations
CVE-2026-71543HighOpenBao is an open source identity-based secrets management system
CVE-2026-46358MediumOpenBao is an open source identity-based secrets management system
CVE-2026-45808HighOpenBao is an open source identity-based secrets management system
CVE-2026-46405Medium· 5.3OpenBao is an open source identity-based secrets management system