CVE-2026-46358
OpenBao's Inline Auth Incorrectly Redacted Headers
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's inline auth functionality incorrectly redacted audit log entries, resulting in non-auth headers being removed and auth-related headers being retained in cleartext. This requires an attacker to compromise access to the audit device. Operators should review leaked source authentication material and rotate it as appropriate. This is fixed in OpenBao v2.5.4.
| CWE | CWE-532 |
| Vendor | openbao |
| Product | openbao |
| Published | Aug 7, 2026 |
| Last Updated | Aug 7, 2026 |
Stay Ahead of the Next One
Get instant alerts for openbao openbao
Be the first to know when new unknown vulnerabilities affecting openbao openbao are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
openbao / openbao
< 2.5.4
References
github.com: https://github.com/openbao/openbao/security/advisories/GHSA-q8cj-789h-vg24 github.com: https://github.com/openbao/openbao/issues/3074 github.com: https://github.com/openbao/openbao/pull/3076 github.com: https://github.com/openbao/openbao/commit/131c6966af4dfb4e1906703436eecdb8f2a3e9df github.com: https://github.com/openbao/openbao/releases/tag/v2.5.4