CVE-2026-42186
OpenBao's Namespace Deletion May Not Delete Data Properly
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
OpenBao is an open source identity-based secrets management system. Prior to 2.5.3, when OpenBao's initial namespace deletion fails, subsequent retries fail to properly remove all data before marking the namespace as deleted. This can affect any outstanding leases as well as potentially leaving unrelated storage entries around. This vulnerability is fixed in 2.5.3.
| CWE | CWE-212 |
| Vendor | openbao |
| Product | openbao |
| Published | May 14, 2026 |
| Last Updated | May 14, 2026 |
Stay Ahead of the Next One
Get instant alerts for openbao openbao
Be the first to know when new unknown vulnerabilities affecting openbao openbao are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
openbao / openbao
< 2.5.3