Improper access control in OpenBao - CVE-2025-64761
Published: April 21, 2026
OpenBao
Detailed vulnerability description
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to improper access control in the identity group subsystem when handling requests to the identity/groups endpoints. A remote privileged user can add a root policy to a group identity group to escalate privileges.
Exploitation requires an operator in the root namespace with access to the identity/groups endpoints but without policy access.