Inclusion of Sensitive Information in Log Files in OpenBao - CVE-2026-46358
Published: May 21, 2026
Vulnerability details
The vulnerability allows a local privileged user to disclose sensitive information.
The vulnerability exists due to improper redaction in inline auth audit log handling when recording audit log entries. A local privileged user can access an audit device containing incorrectly redacted logs to disclose sensitive information.
User interaction is passive, and exploitation requires compromise of access to the audit device.
Affected software
Fedora
openbao
How to mitigate CVE-2026-46358
openbao - addressed in versions 2.5.4-1.el8, 2.5.4-1.el9, 2.5.4-1.el10_2, 2.5.4-1.el10_3, 2.5.4-1.fc42, 2.5.4-1.fc43