Skip to content
openbaoGHSA-p49j-v9wc-wg57

OpenBao's Token Store Allows Cross-Namespace Renewal, Revocation

LowCVE-2026-40264 · Published Apr 21, 2026 · updated Sep 10, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/openbao/openbao
Go
< 0.0.0-20260420162526-f58111d2ca540.0.0-20260420162526-f58111d2ca54
Details and references

### Impact OpenBao's namespaces provide multi-tenant separation. A tenant who leaks token accessors can have their token revoked or renewed by a privileged administrator in another tenant. ### Patches This was addressed in v2.5.3.

CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-1259
Also known as
BIT-openbao-2026-40264, CVE-2026-40264, GO-2026-5526

More openbao advisories

All
DateAdvisory
Apr 21OpenBao's Certificate Authentication Allows Token Renewal With Different Certificate
CVE-2026-39388Low3.1fixed in 0.0.0-20260420160924-abe84e1af4c3
Apr 21OpenBao: Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)
CVE-2026-39396Low3.1fixed in 0.0.0-20260420180337-2b2a901aa9f7
Apr 21OpenBao's SQL Injection in PostgreSQL database secrets engine
CVE-2026-39946Medium4.9fixed in 0.0.0-20260420155735-b596b0882620
May 5OpenBao's Namespace Deletion May Not Delete Data Properly
CVE-2026-42186Lowfixed in 0.0.0-20260420173541-6d2e0506e2b4
Mar 26OpenBao has Reflected XSS in its OIDC authentication error message
CVE-2026-33758Criticalfixed in 0.0.0-20260325133417-6e2b2dd84f0e
Mar 26OpenBao lacks user confirmation for OIDC direct callback mode
CVE-2026-33757Critical9.6fixed in 0.0.0-20260325142553-e32103951925

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.