{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/openbao--0.0.0-20260710001938-2d4ebafec5c5-0.1.0-1.1.5/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:openbao:openbao:*:*:*:*:*:*:*:*"],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["OpenBao (0.1.0 to 1.1.5, \u003c 0.0.0-20260713141742-763625a20721)","OpenBao (\u003c 0.0.0-20260710001938-2d4ebafec5c5, 0.1.0-1.1.5)"],"_cs_severities":["critical"],"_cs_tags":["credential-access","vulnerability","openbao","privilege-escalation","secrets-management","cve-2026-71543"],"_cs_type":"advisory","_cs_vendors":["OpenBao"],"content_html":"\u003cp\u003eOpenBao, an open-source secret management tool, contains a critical vulnerability (CVE-2026-63132) in its recovery mode mechanism. The vulnerability originates from a timing discrepancy in how recovery tokens are verified, allowing an attacker to reconstruct the token via repeated requests. Because the recovery mode is designed for administrative maintenance and bypasses standard access controls, successful extraction of this single recovery token grants an attacker full administrative privileges. This enables unauthorized actors to read or modify any data managed by the OpenBao instance, effectively compromising the entire secrets infrastructure. The vulnerability affects OpenBao versions ranging from 0.1.0 to 1.1.5, as well as specific development builds prior to July 2026. Defenders should prioritize patching to version 2.6.0 immediately.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-63132 results in full administrative access to an organization's OpenBao instance. This leads to the complete compromise of stored secrets, credentials, and API keys. The impact is critical, as it bypasses standard authorization and auditing mechanisms, potentially leading to widespread lateral movement and privilege escalation across the infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all OpenBao instances to version 2.6.0 or later to mitigate CVE-2026-63132.\u003c/li\u003e\n\u003cli\u003eAudit OpenBao access logs for abnormal request patterns targeting the recovery endpoint.\u003c/li\u003e\n\u003cli\u003eRotate all secrets and credentials managed by any OpenBao instance that was exposed to network access during the vulnerable period.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-23T01:55:34Z","date_published":"2026-09-23T01:54:27Z","id":"https://feed.craftedsignal.io/briefs/2026-09-openbao-token-leak/","summary":"OpenBao recovery mode is vulnerable to a timing attack (CVE-2026-63132) that allows an unauthenticated attacker to exfiltrate the recovery token and gain administrative control.","title":"OpenBao Recovery Mode Timing Attack","url":"https://feed.craftedsignal.io/briefs/2026-09-openbao-token-leak/"}],"language":"en","title":"CraftedSignal Threat Feed - OpenBao (\u003c 0.0.0-20260710001938-2d4ebafec5c5, 0.1.0-1.1.5)","version":"https://jsonfeed.org/version/1.1"}