Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-55774— OpenBao: Cross-namespace lease revocation/renewal via canonical sys/leases/{revoke,renew} — incomplete fix of CVE-2026-45808

Quick assessment

Affected
openbao openbao
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

OpenBao 是一个基于身份的开源密钥管理系统。在 2.5.5 版本之前,拥有某个命名空间中 路径访问权限的 OpenBao 用户,在已知其他命名空间中租约 ID 的情况下,可以撤销该其他命名空间中的租约,从而绕过命名空间访问控制列表(ACL)隔离。受影响的租约查找路由逻辑(位于 文件中)使得 和 函数能够解析请求命名空间之外缓存或存储的租约数据,导致一个租户若故意泄露其租约标识符,其租约及底层凭证可能被另一个租户撤销。该问题已在 2.5.5 版本中修复。

CVSS 2.1 · Low

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-55774

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
OpenBao: Cross-namespace lease revocation/renewal via canonical sys/leases/{revoke,renew} — incomplete fix of CVE-2026-45808
Source: CVE Program / CVE List V5
Vulnerability Description
OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, an OpenBao user with access to sys/leases/revoke/:lease_id in one namespace could revoke a lease in another namespace when the foreign lease_id was known, bypassing namespace ACL isolation. The affected lease lookup routing in vault/expiration.go allowed FetchLeaseInfo and loadEntry to resolve cached or stored lease data outside the request namespace, allowing a tenant that intentionally disclosed a lease identifier to have the lease and its underlying credential revoked by another tenant. This issue is fixed in version 2.5.5.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制不正确
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
openbao openbao < 2.5.5 -

II. Public POCs for CVE-2026-55774

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-55774

登录查看更多情报信息。

Patches & Fixes for CVE-2026-55774 (4)

Vendor Advisories for CVE-2026-55774 (1)

Vendor Pages for CVE-2026-55774 (2)

Same Patch Batch · openbao · 2026-09-15 · 4 CVEs total

CVE-2026-55770 6.8 MEDIUM OpenBao: LDAPi ldaputil (wrong escape func)
CVE-2026-55776 6.5 MEDIUM OpenBao: Transit secrets engine crashes on key creation with `derived: true` for asymmetri
CVE-2026-55775 2.3 LOW OpenBao's System Backend allows Unauthorized Management of the containing Namespace

IV. Related Vulnerabilities

V. Comments for CVE-2026-55774

No comments yet


Leave a comment