๐Ÿ” CVE Alert

CVE-2026-77285

UNKNOWN 0.0

OpenBao Agent Writes Secrets to Stdout

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, OpenBao Agent's exec rendering mode could write secrets from env_template to standard output when command/agent/exec/exec.go re-created the template runner after repeated rendering failures, primarily after num_retries was reached. A process supervisor, log collector, or local user able to read that output could obtain the rendered secret values. This issue is fixed in version 2.6.0.

CWE CWE-532
Vendor openbao
Product openbao
Published Sep 23, 2026
Last Updated Sep 23, 2026
Stay Ahead of the Next One

Get instant alerts for openbao openbao

Be the first to know when new unknown vulnerabilities affecting openbao openbao are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

openbao / openbao
< 2.6.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/openbao/openbao/security/advisories/GHSA-444v-8vxr-p36h github.com: https://github.com/openbao/openbao/pull/3494 github.com: https://github.com/openbao/openbao/pull/3495 github.com: https://github.com/openbao/openbao/commit/90272575e5f58b3883fbb0ccb2238e9285722d1a github.com: https://github.com/openbao/openbao/commit/ee3aa4aff72c5176cf02af21eac7158899080878 github.com: https://github.com/openbao/openbao/releases/tag/v2.6.0