LDAP injection in OpenBao - CVE-2026-55770
Published: August 19, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information and modify data by impersonating a different LDAP user.
The vulnerability exists due to improper neutralization of special elements used in an LDAP query in sdk/helper/ldaputil/client.go when constructing LDAP search filters from the username field during login. A remote user can supply a specially crafted username value to disclose sensitive information and modify data by causing OpenBao to bind a token to a different LDAP user.
Exploitation requires the LDAP authentication backend to be configured and the deployment to use Active Directory or UserDN/UserAttr binding.
Affected software
Fedora
openbao
How to mitigate CVE-2026-55770
openbao - addressed in versions 2.5.5-1.el8, 2.5.5-1.el9, 2.5.5-1.el10_2, 2.5.5-1.el10_3, 2.5.5-1.fc43, 2.5.5-1.fc44