Inclusion of Sensitive Information in Log Files in OpenBao - #VU152257
Published: September 25, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper handling of malformed TypeKVPair and TypeHeader parameters in OpenBao plugin audit logging when processing requests containing malformed TypeKVPair or TypeHeader fields. A remote privileged user can send a request containing malformed fields to disclose sensitive information.
User interaction and additional attack preconditions are required for exploitation.