Medium severity6.0NVD Advisory· Published Sep 22, 2026· Updated Sep 22, 2026
OpenBao Skips Stricter Deny Policy for LIST operations
CVE-2026-63131
Description
Impact
When a policy operator has written capabilities = ["deny"] on a path with a trailing wildcard but allowed a broader list operation (e.g., a deny on secrets/metadata/restricted/* but allowed list on secrets/metadata/*), OpenBao would incorrectly allow the operation. This did not impact other operation types.
Patches
This has been patched in OpenBao v2.6.0.
Patches
Vulnerability mechanics
References
8- github.com/advisories/GHSA-xp3c-3jw3-4vcrghsaADVISORY
- github.com/hashicorp/vault/blob/main/CHANGELOG.mdghsa
- github.com/openbao/openbao/commit/2e9625d6cebe4639d051ef53dd6ce7c49914ae6aghsa
- github.com/openbao/openbao/commit/f58d848c139e5ba71aa63103fcfe101972b999fcghsa
- github.com/openbao/openbao/pull/3389ghsa
- github.com/openbao/openbao/pull/3474ghsa
- github.com/openbao/openbao/releases/tag/v2.6.0ghsa
- github.com/openbao/openbao/security/advisories/GHSA-xp3c-3jw3-4vcrghsa
News mentions
0No linked articles in our index yet.