VYPR
Medium severity6.0NVD Advisory· Published Sep 22, 2026· Updated Sep 22, 2026

OpenBao Skips Stricter Deny Policy for LIST operations

CVE-2026-63131

Description

Impact

When a policy operator has written capabilities = ["deny"] on a path with a trailing wildcard but allowed a broader list operation (e.g., a deny on secrets/metadata/restricted/* but allowed list on secrets/metadata/*), OpenBao would incorrectly allow the operation. This did not impact other operation types.

Patches

This has been patched in OpenBao v2.6.0.

Patches

Vulnerability mechanics

References

8

News mentions

0

No linked articles in our index yet.