๐Ÿ” CVE Alert

CVE-2026-55774

UNKNOWN 0.0

OpenBao: Cross-namespace lease revocation/renewal via canonical sys/leases/{revoke,renew} โ€” incomplete fix of CVE-2026-45808

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, an OpenBao user with access to sys/leases/revoke/:lease_id in one namespace could revoke a lease in another namespace when the foreign lease_id was known, bypassing namespace ACL isolation. The affected lease lookup routing in vault/expiration.go allowed FetchLeaseInfo and loadEntry to resolve cached or stored lease data outside the request namespace, allowing a tenant that intentionally disclosed a lease identifier to have the lease and its underlying credential revoked by another tenant. This issue is fixed in version 2.5.5.

CWE CWE-863
Vendor openbao
Product openbao
Published Sep 15, 2026
Last Updated Sep 15, 2026
Stay Ahead of the Next One

Get instant alerts for openbao openbao

Be the first to know when new unknown vulnerabilities affecting openbao openbao are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

openbao / openbao
< 2.5.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/openbao/openbao/security/advisories/GHSA-c36x-h252-g9x2 github.com: https://github.com/openbao/openbao/pull/3307 github.com: https://github.com/openbao/openbao/pull/3310 github.com: https://github.com/openbao/openbao/commit/9ba1413d793223cca67db12434093a2f25fdc540 github.com: https://github.com/openbao/openbao/commit/b20b999dd4044d7b419a5472d8fe08407828be37 github.com: https://github.com/openbao/openbao/releases/tag/v2.5.5 github.com: https://github.com/openbao/openbao/releases/tag/v2.6.0