VYPR
Low severity2.4NVD Advisory· Published Sep 22, 2026· Updated Sep 22, 2026

OpenBao Agent Writes Secrets to Stdout

CVE-2026-77285

Description

Impact

During certain error conditions, OpenBao Agent's exec rendering mode will incorrectly write secrets specified in env_template to stdout. This primarily happens when num_retries is met.

This vulnerability is original to Vault and was reported via the OpenBao security mailing list.

Patches

This is addressed in OpenBao v2.6.0 GA.

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.