openbaoGHSA-444v-8vxr-p36h
OpenBao Agent Writes Secrets to Stdout
LowCVE-2026-77285 · Published Sep 22, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/openbao/openbao Go | < 0.0.0-20260714163218-90272575e5f5 | 0.0.0-20260714163218-90272575e5f5 |
| >= 0.1.0, <= 1.1.5 | No fix yet |
Details and references
### Impact During certain error conditions, OpenBao Agent's exec rendering mode will incorrectly write secrets specified in `env_template` to stdout. This primarily happens when `num_retries` is met. This vulnerability is original to Vault and was reported via the OpenBao security mailing list. ### Patches This is addressed in OpenBao v2.6.0 GA.
- CVSS 4.0
- CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-532
- Also known as
- CVE-2026-77285
- github.com/openbao/openbao/security/advisories/GHSA-444v-8vxr-p36h
- github.com/openbao/openbao/pull/3494
- github.com/openbao/openbao/pull/3495
- github.com/openbao/openbao/commit/90272575e5f58b3883fbb0ccb2238e9285722d1a
- github.com/openbao/openbao/commit/ee3aa4aff72c5176cf02af21eac7158899080878
- github.com/openbao/openbao
- github.com/openbao/openbao/releases/tag/v2.6.0
More openbao advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 22 | OpenBao's Templated Policies Allow Privilege Escalation via Wildcard Characters CVE-2026-71543Highfixed in 0.0.0-20260710001938-2d4ebafec5c5 | High | 0.0.0-20260710001938-2d4ebafec5c5 |
| Sep 22 | OpenBao's Recovery Mode Vulnerable To Token Leakage via Timing Attack CVE-2026-63132Criticalfixed in 0.0.0-20260713141742-763625a20721 | Critical | 0.0.0-20260713141742-763625a20721 |
| Sep 22 | OpenBao Skips Stricter Deny Policy for LIST operations CVE-2026-63131Mediumfixed in 0.0.0-20260713133043-f58d848c139e | Medium | 0.0.0-20260713133043-f58d848c139e |
| Jun 19 | OpenBao: Transit secrets engine crashes on key creation with `derived: true` for asymmetric key types CVE-2026-55776Medium6.5fixed in 0.0.0-20260617104123-db57c62602b2 | Medium6.5 | 0.0.0-20260617104123-db57c62602b2 |
| Jun 19 | OpenBao's System Backend allows Unauthorized Management of the containing Namespace CVE-2026-55775Lowfixed in 0.0.0-20260617103935-d3c1cc64b1ae | Low | 0.0.0-20260617103935-d3c1cc64b1ae |
| Jun 19 | OpenBao: Cross-namespace lease revocation/renewal via canonical sys/leases/{revoke,renew} , incomplete fix of CVE-2026-45808 CVE-2026-55774Lowfixed in 0.0.0-20260617103932-b20b999dd404 | Low | 0.0.0-20260617103932-b20b999dd404 |