<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>OpenBao (&lt; 0.0.0-20260710001938-2d4ebafec5c5, 0.1.0-1.1.5) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/openbao--0.0.0-20260710001938-2d4ebafec5c5-0.1.0-1.1.5/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 23 Sep 2026 01:54:27 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/openbao--0.0.0-20260710001938-2d4ebafec5c5-0.1.0-1.1.5/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>OpenBao Recovery Mode Timing Attack</title><link>https://feed.craftedsignal.io/briefs/2026-09-openbao-token-leak/</link><pubDate>Wed, 23 Sep 2026 01:54:27 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-openbao-token-leak/</guid><description>OpenBao recovery mode is vulnerable to a timing attack (CVE-2026-63132) that allows an unauthenticated attacker to exfiltrate the recovery token and gain administrative control.</description><content:encoded><![CDATA[<p>OpenBao, an open-source secret management tool, contains a critical vulnerability (CVE-2026-63132) in its recovery mode mechanism. The vulnerability originates from a timing discrepancy in how recovery tokens are verified, allowing an attacker to reconstruct the token via repeated requests. Because the recovery mode is designed for administrative maintenance and bypasses standard access controls, successful extraction of this single recovery token grants an attacker full administrative privileges. This enables unauthorized actors to read or modify any data managed by the OpenBao instance, effectively compromising the entire secrets infrastructure. The vulnerability affects OpenBao versions ranging from 0.1.0 to 1.1.5, as well as specific development builds prior to July 2026. Defenders should prioritize patching to version 2.6.0 immediately.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-63132 results in full administrative access to an organization's OpenBao instance. This leads to the complete compromise of stored secrets, credentials, and API keys. The impact is critical, as it bypasses standard authorization and auditing mechanisms, potentially leading to widespread lateral movement and privilege escalation across the infrastructure.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade all OpenBao instances to version 2.6.0 or later to mitigate CVE-2026-63132.</li>
<li>Audit OpenBao access logs for abnormal request patterns targeting the recovery endpoint.</li>
<li>Rotate all secrets and credentials managed by any OpenBao instance that was exposed to network access during the vulnerable period.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>credential-access</category><category>vulnerability</category><category>openbao</category><category>privilege-escalation</category><category>secrets-management</category><category>cve-2026-71543</category></item></channel></rss>