Skip to content
OpenBaoGHSA-6vgr-cp5c-ffx3

OpenBao's SQL Injection in PostgreSQL database secrets engine

Medium4.9CVE-2026-39946 · Published Apr 21, 2026 · updated Sep 10, 2026

### Impact When OpenBao revoked privileges on a role in the PostgreSQL database secrets engine, OpenBao failed to use proper database quoting on schema names provided by PostgreSQL. This could lead to role revocation failures, or more rarely, SQL injection as the management user. This vulnerability was originally from HashiCorp Vault. ### Patches This was addressed in v2.5.3. ### Workarounds Audit table schemas and ensure database users cannot create new schemas and grant privileges on them.

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/openbao/openbao
Go
< 0.0.0-20260420155735-b596b08826200.0.0-20260420155735-b596b0882620
Details and references

More OpenBao advisories

All OpenBao
Advisory
OpenBao's Namespace Deletion May Not Delete Data Properly
LowMay 5
OpenBao's Token Store Allows Cross-Namespace Renewal, Revocation
LowApr 21
OpenBao: Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)
Low3.1Apr 21
OpenBao's Certificate Authentication Allows Token Renewal With Different Certificate
Low3.1Apr 21
OpenBao has Reflected XSS in its OIDC authentication error message
CriticalMar 26
OpenBao lacks user confirmation for OIDC direct callback mode
Critical9.6Mar 26

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.