openbaoGHSA-p49j-v9wc-wg57
OpenBao's Token Store Allows Cross-Namespace Renewal, Revocation
LowCVE-2026-40264 · Published Apr 21, 2026 · updated Sep 10, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/openbao/openbao Go | < 0.0.0-20260420162526-f58111d2ca54 | 0.0.0-20260420162526-f58111d2ca54 |
Details and references
### Impact OpenBao's namespaces provide multi-tenant separation. A tenant who leaks token accessors can have their token revoked or renewed by a privileged administrator in another tenant. ### Patches This was addressed in v2.5.3.
- CVSS 4.0
- CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-1259
- Also known as
- BIT-openbao-2026-40264, CVE-2026-40264, GO-2026-5526
More openbao advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Apr 21 | OpenBao's Certificate Authentication Allows Token Renewal With Different Certificate CVE-2026-39388Low3.1fixed in 0.0.0-20260420160924-abe84e1af4c3 | Low3.1 | 0.0.0-20260420160924-abe84e1af4c3 |
| Apr 21 | OpenBao: Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS) CVE-2026-39396Low3.1fixed in 0.0.0-20260420180337-2b2a901aa9f7 | Low3.1 | 0.0.0-20260420180337-2b2a901aa9f7 |
| Apr 21 | OpenBao's SQL Injection in PostgreSQL database secrets engine CVE-2026-39946Medium4.9fixed in 0.0.0-20260420155735-b596b0882620 | Medium4.9 | 0.0.0-20260420155735-b596b0882620 |
| May 5 | OpenBao's Namespace Deletion May Not Delete Data Properly CVE-2026-42186Lowfixed in 0.0.0-20260420173541-6d2e0506e2b4 | Low | 0.0.0-20260420173541-6d2e0506e2b4 |
| Mar 26 | OpenBao has Reflected XSS in its OIDC authentication error message CVE-2026-33758Criticalfixed in 0.0.0-20260325133417-6e2b2dd84f0e | Critical | 0.0.0-20260325133417-6e2b2dd84f0e |
| Mar 26 | OpenBao lacks user confirmation for OIDC direct callback mode CVE-2026-33757Critical9.6fixed in 0.0.0-20260325142553-e32103951925 | Critical9.6 | 0.0.0-20260325142553-e32103951925 |