Input validation error in OpenBao - #VU152258
Published: September 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to obtain a certificate containing non-validated subject alternative names.
The vulnerability exists due to improper input validation in the PKI ACME certificate issuance functionality when handling ACME certificate requests. A remote attacker can validate an allowed domain and request a certificate containing non-validated subject alternative names to obtain a certificate containing non-validated subject alternative names.
Exploitation requires the PKI ACME feature to be enabled and configured, and the non-validated subject alternative names must be of a type that is not issuable through ACME, such as email addresses.