CVE Tools

Openbao

36 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Openbao, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.

Openbao CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Openbao CVEs per month
MonthCVEs
2024-102
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-051
2025-062
2025-070
2025-087
2025-090
2025-103
2025-111
2025-120
2026-010
2026-020
2026-032
2026-044
2026-051
2026-060
2026-070
2026-083
2026-098

Severity

How the 36 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical27%
  • High1036%
  • Medium1243%
  • Low414%

Latest CVEs

The 15 most recently published vulnerabilities affecting Openbao.

  1. CVE-2026-63132OpenBao's Recovery Mode Vulnerable To Token Leakage via Timing Attack—
  2. CVE-2026-63131OpenBao LIST ACL bypass: a trailing-slash LIST request skips a more-specific deny rule (unported Vault v2.0.3 fix)—
  3. CVE-2026-77285OpenBao Agent Writes Secrets to Stdout—
  4. CVE-2026-71543OpenBao's Templated Policies Allow Privilege Escalation via Wildcard Characters—
  5. CVE-2026-55770OpenBao: LDAPi ldaputil (wrong escape func)6.8
  6. CVE-2026-55776OpenBao: Transit secrets engine crashes on key creation with `derived: true` for asymmetric key types6.5
  7. CVE-2026-55774OpenBao: Cross-namespace lease revocation/renewal via canonical sys/leases/{revoke,renew} — incomplete fix of CVE-2026-45808—
  8. CVE-2026-55775OpenBao's System Backend allows Unauthorized Management of the containing Namespace—
  9. CVE-2026-45808OpenBao's cross-namespace lease revocation via legacy sys/revoke path bypasses ACL—
  10. CVE-2026-46405OpenBao's Kerberos Auth Method Accumulates Unaccessible Tokens5.3
  11. CVE-2026-46358OpenBao's Inline Auth Incorrectly Redacted Headers—
  12. CVE-2026-42186OpenBao's Namespace Deletion May Not Delete Data Properly7.5
  13. CVE-2026-40264OpenBao's Token Store Allows Cross-Namespace Renewal, Revocation2.7
  14. CVE-2026-39396OpenBao has Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)3.1
  15. CVE-2026-39388OpenBao's Certificate Authentication Allows Token Renewal With Different Certificate3.1

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store