CVE-2026-55774
Description
OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, an OpenBao user with access to sys/leases/revoke/:lease_id in one namespace could revoke a lease in another namespace when the foreign lease_id was known, bypassing namespace ACL isolation. The affected lease lookup routing in vault/expiration.go allowed FetchLeaseInfo and loadEntry to resolve cached or stored lease data outside the request namespace, allowing a tenant that intentionally disclosed a lease identifier to have the lease and its underlying credential revoked by another tenant. This issue is fixed in version 2.5.5.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/openbao/openbaoGo | >= 0.1.0, <= 2.5.4 | — |
github.com/openbao/openbaoGo | < 0.0.0-20260617103932-b20b999dd404 | 0.0.0-20260617103932-b20b999dd404 |
Affected products
2- osv-coordsRange: < 0.0.20260723T184607-160000.1.1
Patches
Vulnerability mechanics
References
8- github.com/advisories/GHSA-c36x-h252-g9x2ghsaADVISORY
- github.com/openbao/openbao/commit/b20b999dd4044d7b419a5472d8fe08407828be37nvdWEB
- github.com/openbao/openbao/pull/3307nvdWEB
- github.com/openbao/openbao/releases/tag/v2.5.5nvdWEB
- github.com/openbao/openbao/security/advisories/GHSA-c36x-h252-g9x2nvdWEB
- github.com/openbao/openbao/commit/9ba1413d793223cca67db12434093a2f25fdc540nvd
- github.com/openbao/openbao/pull/3310nvd
- github.com/openbao/openbao/releases/tag/v2.6.0nvd
News mentions
0No linked articles in our index yet.