Incorrect authorization in OpenBao - CVE-2026-55774
Published: August 19, 2026
Vulnerability details
The vulnerability allows a remote user to revoke leases across namespaces.
The vulnerability exists due to incorrect authorization in the sys/leases/revoke/:lease_id endpoint when processing a lease identifier in the request path. A remote privileged user can submit a known lease identifier to revoke leases across namespaces.
A known lease identifier is required for exploitation, and the issue can revoke the underlying credential associated with the lease.
Affected software
Fedora
openbao
How to mitigate CVE-2026-55774
openbao - addressed in versions 2.5.5-1.el8, 2.5.5-1.el9, 2.5.5-1.el10_2, 2.5.5-1.el10_3, 2.5.5-1.fc43, 2.5.5-1.fc44