Skip to content
OpenBaoGHSA-7q7g-x6vg-xpc3

OpenBao lacks user confirmation for OIDC direct callback mode

Critical9.6CVE-2026-33757 · Published Mar 26, 2026 · updated Jul 27, 2026

### Impact OpenBao does not prompt for user confirmation when logging in via JWT/OIDC and a role with `callback_mode` set to `direct`. This allows an attacker to start an authentication request and perform "remote phishing" by having the victim visit the URL and automatically log-in to the session of the attacker. Despite being based on the authorization code flow, the `direct` mode calls back directly to the API and allows an attacker to poll for an OpenBao token until it is issued. ### Patches Version 2.5.2 includes an additional confirmation screen for `direct` type logins that requires manual user interaction in order to finish the authentication. ### Workarounds This issue can be worked around either by removing any roles with `callback_mode=direct` or enforcing confirmation for every session on the token issuer side for the Client ID used by OpenBao.

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/openbao/openbao
Go
< 0.0.0-20260325142553-e321039519250.0.0-20260325142553-e32103951925
Details and references

More OpenBao advisories

All OpenBao
Advisory
OpenBao's Namespace Deletion May Not Delete Data Properly
LowMay 5
OpenBao's Token Store Allows Cross-Namespace Renewal, Revocation
LowApr 21
OpenBao's SQL Injection in PostgreSQL database secrets engine
Medium4.9Apr 21
OpenBao: Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)
Low3.1Apr 21
OpenBao's Certificate Authentication Allows Token Renewal With Different Certificate
Low3.1Apr 21
OpenBao has Reflected XSS in its OIDC authentication error message
CriticalMar 26

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.