๐Ÿ” CVE Alert

CVE-2026-33758

UNKNOWN 0.0

OpenBao has Reflected XSS in its OIDC authentication error message

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.2, OpenBao installations that have an OIDC/JWT authentication method enabled and a role with `callback_mode=direct` configured are vulnerable to XSS via the `error_description` parameter on the page for a failed authentication. This allows an attacker access to the token used in the Web UI by a victim. The `error_description` parameter has been replaced with a static error message in v2.5.2. The vulnerability can be mitigated by removing any roles with `callback_mode` set to `direct`.

CWE CWE-20 CWE-79 CWE-116
Vendor openbao
Product openbao
Published Mar 27, 2026
Last Updated Mar 27, 2026
Stay Ahead of the Next One

Get instant alerts for openbao openbao

Be the first to know when new unknown vulnerabilities affecting openbao openbao are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

openbao / openbao
< 2.5.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/openbao/openbao/security/advisories/GHSA-cpj3-3r2f-xj59 github.com: https://github.com/openbao/openbao/pull/2709 github.com: https://github.com/openbao/openbao/commit/6e2b2dd84f0e47cebc90d6e79609dd5274732662 github.com: https://github.com/openbao/openbao/releases/tag/v2.5.2