OpenBao 是一个基于身份的开源密钥管理系统。在 2.5.5 版本之前,拥有某个命名空间中 路径访问权限的 OpenBao 用户,在已知其他命名空间中租约 ID 的情况下,可以撤销该其他命名空间中的租约,从而绕过命名空间访问控制列表(ACL)隔离。受影响的租约查找路由逻辑(位于 文件中)使得 和 函数能够解析请求命名空间之外缓存或存储的租约数据,导致一个租户若故意泄露其租约标识符,其租约及底层凭证可能被另一个租户撤销。该问题已在 2.5.5 版本中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-55770 | 6.8 MEDIUM | OpenBao: LDAPi ldaputil (wrong escape func) |
| CVE-2026-55776 | 6.5 MEDIUM | OpenBao: Transit secrets engine crashes on key creation with `derived: true` for asymmetri |
| CVE-2026-55775 | 2.3 LOW | OpenBao's System Backend allows Unauthorized Management of the containing Namespace |
No comments yet