Improper access control in OpenBao - #VU152263

 

Improper access control in OpenBao - #VU152263

Published: September 25, 2026


Vulnerability identifier: #VU152263
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to improper access control in the sys/storage/raft/snapshot-force endpoint when replacing Raft storage state. A remote privileged user can replace the plugin catalog with entries for arbitrary binaries to execute arbitrary code.

Only instances using the Raft storage backend are affected. Exploitation requires the instance to subsequently be unsealed.


Affected software

OpenBao

Remediation

Install security update from vendor's website.

OpenBao - addressed in versions 2.6.3, 2.7.0

External References

Related Security Bulletins