CVE-2026-46405

Name
CVE-2026-46405
Description
OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, in OpenBao's Kerberos auth method on the `GET` handler, or when an `Authorization: Negotiate` header is supplied, the response is includes a `logical.Auth` object in addition to an error message. This results in tokens being created with only the default policy, default TTL, and no entity information, which are hidden by the returned error message. No access to these tokens by the caller occurs and the authentication token is not ever made accessible outside of `sys/raw`. This is fixed in OpenBao v2.5.4. As a workaround, users may set a rate limit quota to limit the creation of these paths. As the path is unauthenticated, it isn't possible to deny access to it.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
security-advisories@github.com https://github.com/openbao/openbao/commit/0d82e0a5a3b6a93e8087bcbaf0b11326c12d4f4d
security-advisories@github.com https://github.com/openbao/openbao/pull/3150
security-advisories@github.com https://github.com/openbao/openbao/releases/tag/v2.5.4
security-advisories@github.com https://github.com/openbao/openbao/security/advisories/GHSA-7j6w-vvw2-5f9c

Match rules

CPE URI Source package Min version Max version

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
openbao edge-community 2.5.4-r0 Kevin Daudt <kdaudt@alpinelinux.org> fixed
openbao 3.24-community 2.5.4-r0 Kevin Daudt <kdaudt@alpinelinux.org> fixed
openbao 3.23-community 2.5.4-r0 Kevin Daudt <kdaudt@alpinelinux.org> fixed