Inclusion of Sensitive Information in Log Files in OpenBao - #VU152257

 

Inclusion of Sensitive Information in Log Files in OpenBao - #VU152257

Published: September 25, 2026


Vulnerability identifier: #VU152257
CSH Severity: Low
CVSS v4: 1.8 [CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-532
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper handling of malformed TypeKVPair and TypeHeader parameters in OpenBao plugin audit logging when processing requests containing malformed TypeKVPair or TypeHeader fields. A remote privileged user can send a request containing malformed fields to disclose sensitive information.

User interaction and additional attack preconditions are required for exploitation.


Affected software

OpenBao

Remediation

Install security update from vendor's website.

OpenBao - addressed in versions 2.6.3, 2.7.0

External References

Related Security Bulletins