Improper Authentication in OpenBao - CVE-2026-39388
Published: April 21, 2026
Vulnerability details
The vulnerability allows a remote user to modify token renewal behavior and extend the lifetime of dynamic leases.
The vulnerability exists due to improper certificate binding validation in the certificate authentication method when processing token renewal requests with disable_binding=true. A remote privileged user can present a sibling certificate and key signed by the same CA to modify token renewal behavior and extend the lifetime of dynamic leases.
Exploitation requires knowledge of the original token or its accessor.
Affected software
Fedora
openbao
How to mitigate CVE-2026-39388
openbao - addressed in versions 2.5.3-1.el8, 2.5.3-1.el9, 2.5.3-1.el10_1, 2.5.3-1.el10_2, 2.5.3-1.el10_3, 2.5.3-1.fc42, 2.5.3-1.fc43, 2.5.3-1.fc44
External References
Related Security Bulletins
- Multiple vulnerabilities in Jupyter Notebook
- Fedora EPEL 8 update for openbao
- Fedora EPEL 10.3 update for openbao
- Fedora 43 update for openbao
- Fedora EPEL 10.1 update for openbao
- Fedora 44 update for openbao
- Fedora 42 update for openbao
- Fedora EPEL 10.2 update for openbao
- Fedora EPEL 9 update for openbao