openbao has 27 CVEs on record between 2025 and 2026. Cadence is steady at roughly 7 per quarter. The busiest recent month was April 2026 with 4. The median CVSS is 5.5 (medium), with 3 rated critical. None have a confirmed exploitation report. Most affected products: github.com/openbao/openbao (22), openbao (4), github.com/openbao/openbao/sdk/v2 (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.5
- Publish → KEV
- —
- Last 90 days
- 7 prev 5
Products
- github.com/openbao/openbao 22
- openbao 4
- github.com/openbao/openbao/sdk/v2 1
Worst active — by depth score
CVE-2026-33757Critical· 9.6OpenBao lacks user confirmation for OIDC direct callback mode53CVE-2026-33758CriticalOpenBao has Reflected XSS in its OIDC authentication error message52CVE-2025-54997Critical· 9.1Privileged OpenBao Operator May Execute Code on the Underlying Host50CVE-2026-55770Medium· 6.8OpenBao is an open source identity-based secrets management system49CVE-2026-55776Medium· 6.5OpenBao is an open source identity-based secrets management system48
openbao vulnerabilities
CVEs affecting openbao, newest first. Open any entry for full detail, references, and exploit status.
27 CVEsRSS
CVE-2026-55770Medium· 6.8PoCOpenBao is an open source identity-based secrets management system
OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, OpenBao used EscapeLDAPValue, an RFC 4514 distinguished-name escaping function, where RFC 4515 LDAP search-filter escaping was required in sdk/helper/lda…
CVE-2026-55774Low· 2.1OpenBao is an open source identity-based secrets management system
OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, an OpenBao user with access to sys/leases/revoke/:lease_id in one namespace could revoke a lease in another namespace when the foreign lease_id was known…
CVE-2026-55775Low· 2.3⚖ disputedOpenBao is an open source identity-based secrets management system
OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, OpenBao users granted capabilities on /sys/namespaces/root within a non-root namespace could exploit special handling of the literal root path in namespa…
CVE-2026-55776Medium· 6.5PoCOpenBao is an open source identity-based secrets management system
OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, an authenticated OpenBao caller with write access to transit/keys/* could terminate the server process by setting derived to true while the type paramete…
CVE-2026-45808HighOpenBao is an open source identity-based secrets management system
OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's namespaces provide multi-tenant separation. A tenant who intentionally leaks lease identifiers can have their lease and underlying cred…
CVE-2026-46358MediumOpenBao is an open source identity-based secrets management system
OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's inline auth functionality incorrectly redacted audit log entries, resulting in non-auth headers being removed and auth-related headers …
CVE-2026-46405Medium· 5.3OpenBao is an open source identity-based secrets management system
OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, in OpenBao's Kerberos auth method on the `GET` handler, or when an `Authorization: Negotiate` header is supplied, the response is includes a `log…
CVE-2026-42186LowOpenBao's Namespace Deletion May Not Delete Data Properly
OpenBao's Namespace Deletion May Not Delete Data Properly
CVE-2026-39396Low· 3.1OpenBao: Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)
OpenBao: Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)
CVE-2026-40264LowOpenBao's Token Store Allows Cross-Namespace Renewal, Revocation
OpenBao's Token Store Allows Cross-Namespace Renewal, Revocation
CVE-2026-39388Low· 3.1OpenBao's Certificate Authentication Allows Token Renewal With Different Certificate
OpenBao's Certificate Authentication Allows Token Renewal With Different Certificate
CVE-2026-39946Medium· 4.9OpenBao's SQL Injection in PostgreSQL database secrets engine
OpenBao's SQL Injection in PostgreSQL database secrets engine
CVE-2026-33758CriticalOpenBao has Reflected XSS in its OIDC authentication error message
OpenBao has Reflected XSS in its OIDC authentication error message
CVE-2026-33757Critical· 9.6OpenBao lacks user confirmation for OIDC direct callback mode
OpenBao lacks user confirmation for OIDC direct callback mode
CVE-2025-64761HighOpenBao is Vulnerable to Privileged Operator Identity Group Root Escalation
OpenBao is Vulnerable to Privileged Operator Identity Group Root Escalation
CVE-2025-62705MediumOpenBao and Vault Leak []byte Fields in Audit Logs
OpenBao and Vault Leak []byte Fields in Audit Logs
CVE-2025-62513MediumOpenBao leaks HTTPRawBody in Audit Logs
OpenBao leaks HTTPRawBody in Audit Logs
CVE-2025-59043High· 7.5OpenBao has potential Denial of Service vulnerability when processing malicious unauthenticated JSON requests
OpenBao has potential Denial of Service vulnerability when processing malicious unauthenticated JSON requests
CVE-2025-54997Critical· 9.1Privileged OpenBao Operator May Execute Code on the Underlying Host
Privileged OpenBao Operator May Execute Code on the Underlying Host
CVE-2025-54996High· 7.2OpenBao Root Namespace Operator May Elevate Token Privileges
OpenBao Root Namespace Operator May Elevate Token Privileges
CVE-2025-55003Medium· 5.7OpenBao Login MFA Bypass of Rate Limiting and TOTP Token Reuse
OpenBao Login MFA Bypass of Rate Limiting and TOTP Token Reuse
CVE-2025-54998Medium· 5.3OpenBao Userpass and LDAP User Lockout Bypass
OpenBao Userpass and LDAP User Lockout Bypass
CVE-2025-54999Low· 3.7OpenBao has a Timing Side-Channel in the Userpass Auth Method
OpenBao has a Timing Side-Channel in the Userpass Auth Method
CVE-2025-55000Medium· 6.5OpenBao TOTP Secrets Engine Code Reuse
OpenBao TOTP Secrets Engine Code Reuse
CVE-2025-55001Medium· 6.5OpenBao LDAP MFA Enforcement Bypass When Using Username As Alias
OpenBao LDAP MFA Enforcement Bypass When Using Username As Alias
CVE-2025-52894MediumOpenBao allows cancellation of root rekey and recovery rekey operations without authentication
OpenBao allows cancellation of root rekey and recovery rekey operations without authentication
CVE-2025-52893Medium· 4.5OpenBao Inserts Sensitive Information into Log File when processing malformed data
OpenBao Inserts Sensitive Information into Log File when processing malformed data