Skip to content
OpenBaoGHSA-jg74-mwgw-v6x3

Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default

High7.5CVE-2024-7594 · Published Sep 26, 2024 · updated Sep 10, 2026

Vault’s SSH secrets engine did not require the valid_principals list to contain a value by default. If the valid_principals and default_user fields of the SSH secrets engine configuration are not set, an SSH certificate requested by an authorized user to Vault’s SSH secrets engine could be used to authenticate as any user on the host. Fixed in Vault Community Edition 1.17.6, and in Vault Enterprise 1.17.6, 1.16.10, and 1.15.15.

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/openbao/openbao
Go
>= 0.1.0No fix yet
< 0.0.0-20241003222810-d5b4e92246980.0.0-20241003222810-d5b4e9224698
github.com/hashicorp/vault
Go
>= 1.7.7, < 1.17.61.17.6
Details and references

More OpenBao advisories

All OpenBao
Advisory
OpenBao TOTP Secrets Engine Code Reuse
Medium6.5Aug 8, 2025
OpenBao has a Timing Side-Channel in the Userpass Auth Method
Low3.7Aug 8, 2025
OpenBao Userpass and LDAP User Lockout Bypass
Medium5.3Aug 8, 2025
Privileged OpenBao Operator May Execute Code on the Underlying Host
Critical9.1Aug 8, 2025
OpenBao Root Namespace Operator May Elevate Token Privileges
High7.2Aug 8, 2025
OpenBao allows cancellation of root rekey and recovery rekey operations without authentication
MediumJun 26, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.