Skip to content
openbaoGHSA-444v-8vxr-p36h

OpenBao Agent Writes Secrets to Stdout

LowCVE-2026-77285 · Published Sep 22, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/openbao/openbao
Go
< 0.0.0-20260714163218-90272575e5f50.0.0-20260714163218-90272575e5f5
>= 0.1.0, <= 1.1.5No fix yet
Details and references

### Impact During certain error conditions, OpenBao Agent's exec rendering mode will incorrectly write secrets specified in `env_template` to stdout. This primarily happens when `num_retries` is met. This vulnerability is original to Vault and was reported via the OpenBao security mailing list. ### Patches This is addressed in OpenBao v2.6.0 GA.

CVSS 4.0
CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-532
Also known as
CVE-2026-77285

More openbao advisories

All
DateAdvisory
Sep 22OpenBao's Templated Policies Allow Privilege Escalation via Wildcard Characters
CVE-2026-71543Highfixed in 0.0.0-20260710001938-2d4ebafec5c5
Sep 22OpenBao's Recovery Mode Vulnerable To Token Leakage via Timing Attack
CVE-2026-63132Criticalfixed in 0.0.0-20260713141742-763625a20721
Sep 22OpenBao Skips Stricter Deny Policy for LIST operations
CVE-2026-63131Mediumfixed in 0.0.0-20260713133043-f58d848c139e
Jun 19OpenBao: Transit secrets engine crashes on key creation with `derived: true` for asymmetric key types
CVE-2026-55776Medium6.5fixed in 0.0.0-20260617104123-db57c62602b2
Jun 19OpenBao's System Backend allows Unauthorized Management of the containing Namespace
CVE-2026-55775Lowfixed in 0.0.0-20260617103935-d3c1cc64b1ae
Jun 19OpenBao: Cross-namespace lease revocation/renewal via canonical sys/leases/{revoke,renew} , incomplete fix of CVE-2026-45808
CVE-2026-55774Lowfixed in 0.0.0-20260617103932-b20b999dd404

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.