Inclusion of Sensitive Information in Log Files in OpenBao - CVE-2026-46358

 

Inclusion of Sensitive Information in Log Files in OpenBao - CVE-2026-46358

Published: May 21, 2026


Vulnerability identifier: #VU132076
CSH Severity: Medium
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-46358
CWE-ID: CWE-532
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local privileged user to disclose sensitive information.

The vulnerability exists due to improper redaction in inline auth audit log handling when recording audit log entries. A local privileged user can access an audit device containing incorrectly redacted logs to disclose sensitive information.

User interaction is passive, and exploitation requires compromise of access to the audit device.


Affected software

OpenBao
Fedora
openbao

How to mitigate CVE-2026-46358

Install security update from vendor's website.

OpenBao - update to 2.5.4
openbao - addressed in versions 2.5.4-1.el8, 2.5.4-1.el9, 2.5.4-1.el10_2, 2.5.4-1.el10_3, 2.5.4-1.fc42, 2.5.4-1.fc43

External References

Related Security Bulletins