๐Ÿ” CVE Alert

CVE-2026-63131

UNKNOWN 0.0

OpenBao LIST ACL bypass: a trailing-slash LIST request skips a more-specific deny rule (unported Vault v2.0.3 fix)

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, OpenBao's vault/policy/acl.go could evaluate a broader wildcard ACL grant before more-specific trailing-wildcard ACL paths with capabilities = ["deny"] for a LIST operation. When a parent path permitted LIST and a child path was denied, the trailing-slash lookup could therefore allow listing the denied path. Other operation types are outside the repository advisory's affected scope. This issue is fixed in version 2.6.0.

CWE CWE-863
Vendor openbao
Product openbao
Published Sep 23, 2026
Stay Ahead of the Next One

Get instant alerts for openbao openbao

Be the first to know when new unknown vulnerabilities affecting openbao openbao are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

openbao / openbao
< 2.6.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/openbao/openbao/security/advisories/GHSA-xp3c-3jw3-4vcr github.com: https://github.com/openbao/openbao/pull/3389 github.com: https://github.com/openbao/openbao/pull/3474 github.com: https://github.com/openbao/openbao/commit/2e9625d6cebe4639d051ef53dd6ce7c49914ae6a github.com: https://github.com/openbao/openbao/commit/f58d848c139e5ba71aa63103fcfe101972b999fc github.com: https://github.com/hashicorp/vault/blob/main/CHANGELOG.md#203 github.com: https://github.com/openbao/openbao/releases/tag/v2.6.0