Vendor
OpenBao Recovery Mode Timing Attack
2 TTPsOpenBao recovery mode is vulnerable to a timing attack (CVE-2026-63132) that allows an unauthenticated attacker to exfiltrate the recovery token and gain administrative control.
Security Control Bypass Vulnerability in OpenBao
1 TTPA vulnerability in OpenBao allows remote, unauthenticated attackers to bypass security controls, potentially leading to unauthorized access to sensitive secrets and data.
OpenBao Cross-Namespace Lease Revocation via Legacy sys/revoke Path
2 rules 1 TTPOpenBao versions up to 2.5.3 allow cross-namespace lease revocation by exploiting legacy sys/revoke endpoints, potentially leading to unauthorized credential access and denial of service.
OpenBao Reflected XSS Vulnerability in OIDC Authentication Error Message
2 rules 1 TTPOpenBao installations with OIDC/JWT authentication enabled and roles with `callback_mode=direct` are vulnerable to reflected XSS via the `error_description` parameter, allowing attackers to steal Web UI tokens; patched in v2.5.2.