๐Ÿ” CVE Alert

CVE-2026-42186

UNKNOWN 0.0

OpenBao's Namespace Deletion May Not Delete Data Properly

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

OpenBao is an open source identity-based secrets management system. Prior to 2.5.3, when OpenBao's initial namespace deletion fails, subsequent retries fail to properly remove all data before marking the namespace as deleted. This can affect any outstanding leases as well as potentially leaving unrelated storage entries around. This vulnerability is fixed in 2.5.3.

CWE CWE-212
Vendor openbao
Product openbao
Published May 14, 2026
Last Updated May 14, 2026
Stay Ahead of the Next One

Get instant alerts for openbao openbao

Be the first to know when new unknown vulnerabilities affecting openbao openbao are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

openbao / openbao
< 2.5.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/openbao/openbao/security/advisories/GHSA-vv66-6rp4-wr4f github.com: https://github.com/openbao/openbao/commit/6d2e0506e2b41be0eaa6643bf7b4efc9a2c09445 github.com: https://github.com/openbao/openbao/releases/tag/v2.5.3