OpenBao是OpenBao开源的一个敏感数据管理软件。 OpenBao 2.5.3之前版本存在安全漏洞,该漏洞源于命名空间多租户分离问题,可能导致泄露令牌访问器的租户被其他租户的特权管理员撤销或续订令牌。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-39396 | 3.1 LOW | OpenBao has Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS) |
| CVE-2026-39388 | OpenBao's Certificate Authentication Allows Token Renewal With Different Certificate | |
| CVE-2026-39946 | OpenBao allows SQL Injection in PostgreSQL database secrets engine |
No comments yet