Path Traversal: \'../filedir\' in OpenBao - #VU152262
Published: September 25, 2026
Vulnerability details
The vulnerability allows a remote user to perform unauthorized actions across namespaces.
The vulnerability exists due to path traversal in the ACL policy cache when resolving specially crafted policy names. A remote user can attach specially crafted policy names to tokens to perform unauthorized actions across namespaces.
The referenced policies must be present in the in-memory LRU policy cache when the token is created and when it is used.