VulnSea

openbao has 27 CVEs on record between 2025 and 2026. Cadence is steady at roughly 7 per quarter. The busiest recent month was April 2026 with 4. The median CVSS is 5.5 (medium), with 3 rated critical. None have a confirmed exploitation report. Most affected products: github.com/openbao/openbao (22), openbao (4), github.com/openbao/openbao/sdk/v2 (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
5.5
Publish → KEV
Last 90 days
7 prev 5

Products

  • github.com/openbao/openbao 22
  • openbao 4
  • github.com/openbao/openbao/sdk/v2 1
27
Total CVEs
3
Critical
0
CISA KEV
0
Exploited

openbao vulnerabilities

CVEs affecting openbao, newest first. Open any entry for full detail, references, and exploit status.

27 CVEsRSS

CVE-2026-55770Medium· 6.8PoC
1w ago

OpenBao is an open source identity-based secrets management system

OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, OpenBao used EscapeLDAPValue, an RFC 4514 distinguished-name escaping function, where RFC 4515 LDAP search-filter escaping was required in sdk/helper/lda…

Twilightopenbao · openbaoEPSS 0.45%via NVD
CVE-2026-55774Low· 2.1
1w ago

OpenBao is an open source identity-based secrets management system

OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, an OpenBao user with access to sys/leases/revoke/:lease_id in one namespace could revoke a lease in another namespace when the foreign lease_id was known…

Sunlitopenbao · openbaoEPSS 0.44%via NVD
CVE-2026-55775Low· 2.3⚖ disputed
1w ago

OpenBao is an open source identity-based secrets management system

OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, OpenBao users granted capabilities on /sys/namespaces/root within a non-root namespace could exploit special handling of the literal root path in namespa…

Sunlitopenbao · openbaoEPSS 0.36%via NVD
CVE-2026-55776Medium· 6.5PoC
1w ago

OpenBao is an open source identity-based secrets management system

OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, an authenticated OpenBao caller with write access to transit/keys/* could terminate the server process by setting derived to true while the type paramete…

Twilightopenbao · openbaoEPSS 0.46%via NVD
CVE-2026-45808High
1mo ago

OpenBao is an open source identity-based secrets management system

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's namespaces provide multi-tenant separation. A tenant who intentionally leaks lease identifiers can have their lease and underlying cred…

Twilightopenbao · github.com/openbao/openbaoEPSS 0.31%via NVD
CVE-2026-46358Medium
1mo ago

OpenBao is an open source identity-based secrets management system

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's inline auth functionality incorrectly redacted audit log entries, resulting in non-auth headers being removed and auth-related headers …

Sunlitopenbao · github.com/openbao/openbaoEPSS 0.23%via NVD
CVE-2026-46405Medium· 5.3
1mo ago

OpenBao is an open source identity-based secrets management system

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, in OpenBao's Kerberos auth method on the `GET` handler, or when an `Authorization: Negotiate` header is supplied, the response is includes a `log…

Sunlitopenbao · github.com/openbao/openbaoEPSS 0.36%via NVD
CVE-2026-42186Low
4mo ago

OpenBao's Namespace Deletion May Not Delete Data Properly

OpenBao's Namespace Deletion May Not Delete Data Properly

Sunlitopenbao · github.com/openbao/openbaoEPSS 0.25%via OSV
CVE-2026-39396Low· 3.1
5mo ago

OpenBao: Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)

OpenBao: Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)

Sunlitopenbao · github.com/openbao/openbaoEPSS 0.22%via OSV
CVE-2026-40264Low
5mo ago

OpenBao's Token Store Allows Cross-Namespace Renewal, Revocation

OpenBao's Token Store Allows Cross-Namespace Renewal, Revocation

Sunlitopenbao · github.com/openbao/openbaoEPSS 0.30%via OSV
CVE-2026-39388Low· 3.1
5mo ago

OpenBao's Certificate Authentication Allows Token Renewal With Different Certificate

OpenBao's Certificate Authentication Allows Token Renewal With Different Certificate

Sunlitopenbao · github.com/openbao/openbaoEPSS 0.10%via OSV
CVE-2026-39946Medium· 4.9
5mo ago

OpenBao's SQL Injection in PostgreSQL database secrets engine

OpenBao's SQL Injection in PostgreSQL database secrets engine

Sunlitopenbao · github.com/openbao/openbaoEPSS 0.24%via OSV
CVE-2026-33758Critical
6mo ago

OpenBao has Reflected XSS in its OIDC authentication error message

OpenBao has Reflected XSS in its OIDC authentication error message

Midnightopenbao · github.com/openbao/openbaoEPSS 0.29%via OSV
CVE-2026-33757Critical· 9.6
6mo ago

OpenBao lacks user confirmation for OIDC direct callback mode

OpenBao lacks user confirmation for OIDC direct callback mode

Midnightopenbao · github.com/openbao/openbaoEPSS 0.41%via OSV
CVE-2025-64761High
10mo ago

OpenBao is Vulnerable to Privileged Operator Identity Group Root Escalation

OpenBao is Vulnerable to Privileged Operator Identity Group Root Escalation

Twilightopenbao · github.com/openbao/openbaoEPSS 0.36%via OSV
CVE-2025-62705Medium
11mo ago

OpenBao and Vault Leak []byte Fields in Audit Logs

OpenBao and Vault Leak []byte Fields in Audit Logs

Sunlitopenbao · github.com/openbao/openbaoEPSS 0.31%via OSV
CVE-2025-62513Medium
11mo ago

OpenBao leaks HTTPRawBody in Audit Logs

OpenBao leaks HTTPRawBody in Audit Logs

Sunlitopenbao · github.com/openbao/openbaoEPSS 0.29%via OSV
CVE-2025-59043High· 7.5
11mo ago

OpenBao has potential Denial of Service vulnerability when processing malicious unauthenticated JSON requests

OpenBao has potential Denial of Service vulnerability when processing malicious unauthenticated JSON requests

Twilightopenbao · github.com/openbao/openbaoEPSS 0.69%via OSV
CVE-2025-54997Critical· 9.1
1y ago

Privileged OpenBao Operator May Execute Code on the Underlying Host

Privileged OpenBao Operator May Execute Code on the Underlying Host

Midnightopenbao · github.com/openbao/openbaoEPSS 0.38%via OSV
CVE-2025-54996High· 7.2
1y ago

OpenBao Root Namespace Operator May Elevate Token Privileges

OpenBao Root Namespace Operator May Elevate Token Privileges

Twilightopenbao · github.com/openbao/openbaoEPSS 0.31%via OSV
CVE-2025-55003Medium· 5.7
1y ago

OpenBao Login MFA Bypass of Rate Limiting and TOTP Token Reuse

OpenBao Login MFA Bypass of Rate Limiting and TOTP Token Reuse

Sunlitopenbao · github.com/openbao/openbaoEPSS 0.20%via OSV
CVE-2025-54998Medium· 5.3
1y ago

OpenBao Userpass and LDAP User Lockout Bypass

OpenBao Userpass and LDAP User Lockout Bypass

Sunlitopenbao · github.com/openbao/openbaoEPSS 0.21%via OSV
CVE-2025-54999Low· 3.7
1y ago

OpenBao has a Timing Side-Channel in the Userpass Auth Method

OpenBao has a Timing Side-Channel in the Userpass Auth Method

Sunlitopenbao · github.com/openbao/openbaoEPSS 0.19%via OSV
CVE-2025-55000Medium· 6.5
1y ago

OpenBao TOTP Secrets Engine Code Reuse

OpenBao TOTP Secrets Engine Code Reuse

Sunlitopenbao · github.com/openbao/openbaoEPSS 0.21%via OSV
CVE-2025-55001Medium· 6.5
1y ago

OpenBao LDAP MFA Enforcement Bypass When Using Username As Alias

OpenBao LDAP MFA Enforcement Bypass When Using Username As Alias

Sunlitopenbao · github.com/openbao/openbaoEPSS 0.22%via OSV
CVE-2025-52894Medium
1y ago

OpenBao allows cancellation of root rekey and recovery rekey operations without authentication

OpenBao allows cancellation of root rekey and recovery rekey operations without authentication

Sunlitopenbao · github.com/openbao/openbaoEPSS 0.37%via OSV
CVE-2025-52893Medium· 4.5
1y ago

OpenBao Inserts Sensitive Information into Log File when processing malformed data

OpenBao Inserts Sensitive Information into Log File when processing malformed data

Sunlitopenbao · github.com/openbao/openbao/sdk/v2EPSS 0.30%via OSV
openbao vulnerabilities (CVEs) · VulnSea