Skip to content
OpenBaoGHSA-2q8q-8fgw-9p6p

OpenBao LDAP MFA Enforcement Bypass When Using Username As Alias

Medium6.5CVE-2025-55001 · Published Aug 8, 2025 · updated Jul 27, 2026

### Impact OpenBao allows assignment of policies and MFA attribution based upon entity aliases, chosen by the underlying auth method. When using the `username_as_alias=true` parameter in the LDAP auth method, the caller-supplied username is used verbatim without normalization, allowing an attacker to bypass alias-specific MFA requirements. ### Patches OpenBao v2.3.2 will patch this issue. ### Workarounds LDAP methods are only vulnerable if using `username_as_alias=true`. Remove all usage of this parameter and update any entity aliases accordingly. ### References This issue was disclosed to HashiCorp and is the OpenBao equivalent of the following tickets: - https://discuss.hashicorp.com/t/hcsec-2025-20-vault-ldap-mfa-enforcement-bypass-when-using-username-as-alias/76092 - https://nvd.nist.gov/vuln/detail/CVE-2025-6013

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/openbao/openbao
Go
>= 0.1.0, < 2.3.22.3.2
< 0.0.0-20250807212521-c52795c1ef740.0.0-20250807212521-c52795c1ef74
Details and references

More OpenBao advisories

All OpenBao
Advisory
OpenBao Login MFA Bypass of Rate Limiting and TOTP Token Reuse
Medium5.7Aug 8, 2025
OpenBao TOTP Secrets Engine Code Reuse
Medium6.5Aug 8, 2025
OpenBao has a Timing Side-Channel in the Userpass Auth Method
Low3.7Aug 8, 2025
OpenBao Userpass and LDAP User Lockout Bypass
Medium5.3Aug 8, 2025
Privileged OpenBao Operator May Execute Code on the Underlying Host
Critical9.1Aug 8, 2025
OpenBao Root Namespace Operator May Elevate Token Privileges
High7.2Aug 8, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.