Improper access control in OpenBao - #VU152263
Published: September 25, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper access control in the sys/storage/raft/snapshot-force endpoint when replacing Raft storage state. A remote privileged user can replace the plugin catalog with entries for arbitrary binaries to execute arbitrary code.
Only instances using the Raft storage backend are affected. Exploitation requires the instance to subsequently be unsealed.