SB2025102835 - Multiple vulnerabilities in OpenBao
Published: October 28, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 7 secuirty vulnerabilities.
1) Improper privilege management (CVE-ID: CVE-2025-54997)
The vulnerability allows a remote user to escalate privileges within the application.
The vulnerability exists due to improper privilege management within the API. A remote user with privileged API access can perform actions otherwise restricted to their account.
2) Improper Restriction of Excessive Authentication Attempts (CVE-ID: CVE-2025-54998)
The vulnerability allows a remote attacker to bypass automatic lockout mechanism.
The vulnerability exists due to an error in the OpenBao Userpass and LDAP auth systems. A remote user attacker can bypass automatic user lockout mechanism and perform brute-force attacks.
3) Observable discrepancy (CVE-ID: CVE-2025-54999)
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to timing difference between non-existent users and users with stored credentials when userpass auth method is used. A remote attacker can enumerate existing application users.
4) Improper authentication (CVE-ID: CVE-2025-55000)
The vulnerability allows a remote user to bypass MFA authentication.
The vulnerability exists due to an error caused by an unexpected normalization in the underlying TOTP library. A remote user can bypass MFA authentication and gain unauthorized access to the application.
5) Protection Mechanism Failure (CVE-ID: CVE-2025-55001)
The vulnerability allows a remote user to bypass MFA enforcement.
The vulnerability exists due to insufficient implementation of security measures when handling LDAP authentication requests. A remote user can bypass MFA enforcement and gain unauthorized access to the application.
6) Improper Restriction of Excessive Authentication Attempts (CVE-ID: CVE-2025-55003)
The vulnerability allows a remote attacker to brute-force one time passwords.
The vulnerability exists due to an error caused by normalization applied by the underlying TOTP library, which lead to code with a whitespace were accepted. Such a whitespace could bypass internal rate limiting of the MFA method and allow reuse of existing MFA codes.
7) Improper privilege management (CVE-ID: CVE-2025-54996)
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to improper privilege management. A remote user with access to highly-privileged identity entity systems in root namespaces were able to increase their scope directly to the root policy.
Remediation
Install update from vendor's website.
References
- https://discuss.hashicorp.com/t/hcsec-2025-14-privileged-vault-operator-may-execute-code-on-the-underlying-host/76033
- https://github.com/openbao/openbao/pull/1634
- https://github.com/openbao/openbao/releases/tag/v2.3.2
- https://github.com/openbao/openbao/security/advisories/GHSA-xp75-r577-cvhp
- https://discuss.hashicorp.com/t/hcsec-2025-16-vault-userpass-and-ldap-user-lockout-bypass/76035
- https://github.com/openbao/openbao/commit/c52795c1ef746c7f2c510f9225aa8ccbbd44f9fc
- https://github.com/openbao/openbao/security/advisories/GHSA-j3xv-7fxp-gfhx
- https://discuss.hashicorp.com/t/hcsec-2025-15-timing-side-channel-in-vault-s-userpass-auth-method/76034
- https://discuss.hashicorp.com/t/hcsec-2025-21-vault-user-enumeration-in-userpass-auth-method/76095
- https://github.com/openbao/openbao/commit/4d9b5d3d6486ab9fbd5b644173fa0097015d6626
- https://github.com/openbao/openbao/security/advisories/GHSA-hh28-h22f-8357
- https://discuss.hashicorp.com/t/hcsec-2025-17-vault-totp-secrets-engine-code-reuse/76036
- https://github.com/openbao/openbao/commit/183891f8d535d5b6eb3d79fda8200cade6de99e1
- https://github.com/openbao/openbao/security/advisories/GHSA-f7c3-mhj2-9pvg
- https://discuss.hashicorp.com/t/hcsec-2025-20-vault-ldap-mfa-enforcement-bypass-when-using-username-as-alias/76092
- https://github.com/openbao/openbao/security/advisories/GHSA-2q8q-8fgw-9p6p
- https://discuss.hashicorp.com/t/hcsec-2025-19-vault-login-mfa-bypass-of-rate-limiting-and-totp-token-reuse/76038
- https://github.com/openbao/openbao/commit/8340a6918f6c41d8f75b6c3845c376d9dc32ed19
- https://github.com/openbao/openbao/security/advisories/GHSA-rxp7-9q75-vj3p
- https://github.com/openbao/openbao/pull/1627
- https://github.com/openbao/openbao/security/advisories/GHSA-vf84-mxrq-crqc