Low severity2.4NVD Advisory· Published Sep 22, 2026· Updated Sep 22, 2026
OpenBao Agent Writes Secrets to Stdout
CVE-2026-77285
Description
Impact
During certain error conditions, OpenBao Agent's exec rendering mode will incorrectly write secrets specified in env_template to stdout. This primarily happens when num_retries is met.
This vulnerability is original to Vault and was reported via the OpenBao security mailing list.
Patches
This is addressed in OpenBao v2.6.0 GA.
Patches
Vulnerability mechanics
References
7- github.com/advisories/GHSA-444v-8vxr-p36hghsaADVISORY
- github.com/openbao/openbao/commit/90272575e5f58b3883fbb0ccb2238e9285722d1aghsa
- github.com/openbao/openbao/commit/ee3aa4aff72c5176cf02af21eac7158899080878ghsa
- github.com/openbao/openbao/pull/3494ghsa
- github.com/openbao/openbao/pull/3495ghsa
- github.com/openbao/openbao/releases/tag/v2.6.0ghsa
- github.com/openbao/openbao/security/advisories/GHSA-444v-8vxr-p36hghsa
News mentions
0No linked articles in our index yet.