๐Ÿ” CVE Alert

CVE-2026-45808

UNKNOWN 0.0

OpenBao's cross-namespace lease revocation via legacy sys/revoke path bypasses ACL

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's namespaces provide multi-tenant separation. A tenant who intentionally leaks lease identifiers can have their lease and underlying credential revoked or renewed by a user in another tenant via the legacy, undocumented `sys/revoke` and `sys/renew` endpoints. This is fixed in OpenBao v2.5.4.

CWE CWE-863
Vendor openbao
Product openbao
Published Aug 7, 2026
Stay Ahead of the Next One

Get instant alerts for openbao openbao

Be the first to know when new unknown vulnerabilities affecting openbao openbao are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

openbao / openbao
< 2.5.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/openbao/openbao/security/advisories/GHSA-v8v8-cm84-m686 github.com: https://github.com/openbao/openbao/pull/3152 github.com: https://github.com/openbao/openbao/commit/c0495646b41cea0e3f5a1030132e9cf5c2375b5c github.com: https://github.com/openbao/openbao/releases/tag/v2.5.4