CVE-2026-46358

MEDIUM CVSS 4.0: 5.4 EPSS 0.15%
Updated Aug 11, 2026
Openbao
Parameter Value
CVSS 5.4 (MEDIUM)
Type CWE-532
Vendor Openbao
Public PoC No

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's inline auth functionality incorrectly redacted audit log entries, resulting in non-auth headers being removed and auth-related headers being retained in cleartext. This requires an attacker to compromise access to the audit device.

Operators should review leaked source authentication material and rotate it as appropriate. This is fixed in OpenBao v2.5.4.

Attack Parameters

Attack Vector
Local
Requires local access
Attack Complexity
Low
Easy to exploit
Attack Requirements
Present
Additional conditions required
Privileges Required
High
Admin privileges needed
User Interaction
Passive
Minimal interaction

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
High
Complete denial of service

CVSS Vector v4.0

Weakness Type (CWE)

Vulnerable Products

openbao:openbao