๐Ÿ” CVE Alert

CVE-2025-64761

UNKNOWN 0.0

OpenBao Privileged Operator Identity Group Root Escalation

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

OpenBao is an open source identity-based secrets management system. Prior to version 2.4.4, a privileged operator could use the identity group subsystem to add a root policy to a group identity group, escalating their or another user's permissions in the system. Specifically this is an issue when: an operator in the root namespace has access to identity/groups endpoints and an operator does not have policy access. Otherwise, an operator with policy access could create or modify an existing policy to grant root-equivalent permissions through the sudo capability. This issue has been patched in version 2.4.4.

CWE CWE-266
Vendor openbao
Product openbao
Published Nov 25, 2025
Last Updated Feb 26, 2026
Stay Ahead of the Next One

Get instant alerts for openbao openbao

Be the first to know when new unknown vulnerabilities affecting openbao openbao are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

openbao / openbao
< 2.4.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/openbao/openbao/security/advisories/GHSA-7ff4-jw48-3436 github.com: https://github.com/openbao/openbao/pull/2143 github.com: https://github.com/openbao/openbao/commit/16bb0ccd37a502930a289d434cbe4e7b4edd66e5