Improper access control in OpenBao - #VU152261
Published: September 25, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to improper access control in the Agent and Proxy quit endpoints when handling requests without the required X-Vault-Header. A remote privileged user can send a request without the required header to cause a denial of service.
The issue affects Agent and Proxy services configured with require_request_header = true.