OpenBaoGHSA-v8v8-cm84-m686
OpenBao's cross-namespace lease revocation via legacy sys/revoke path bypasses ACL
HighCVE-2026-45808 · Published May 28, 2026 · updated Aug 17, 2026
# Impact OpenBao's namespaces provide multi-tenant separation. A tenant who intentionally leaks lease identifiers can have their lease and underlying credential revoked or renewed by a user in another tenant via the legacy, undocumented `sys/revoke` and `sys/renew` endpoints. # Patch This will be addressed in v2.5.4.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/openbao/openbao Go | < 2.5.4 | 2.5.4 |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-863
- Also known as
- BIT-openbao-2026-45808, CVE-2026-45808, GO-2026-5657
More OpenBao advisories
All OpenBao| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jun 19 | OpenBao: Transit secrets engine crashes on key creation with `derived: true` for asymmetric key types | Medium6.5 | 0.0.0-20260617104123-db57c62602b2 |
| Jun 19 | OpenBao's System Backend allows Unauthorized Management of the containing Namespace | Low | 0.0.0-20260617103935-d3c1cc64b1ae |
| Jun 19 | OpenBao: improper authorization | Low | 0.0.0-20260617103932-b20b999dd404 |
| Jun 19 | OpenBao: LDAPi ldaputil (wrong escape func) | Medium6.8 | 0.0.0-20260617104213-10b7825c714c |
| May 28 | OpenBao's Kerberos Auth Method Accumulates Unaccessible Tokens | Medium5.3 | 2.5.4 |
| May 28 | OpenBao's Inline Auth Incorrectly Redacted Headers | Medium | 2.5.4 |