CVE-2026-45808
Received Received - Intake

Privilege Escalation in OpenBao via Lease Identifier Exposure

Vulnerability report for CVE-2026-45808, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-07

Last updated on: 2026-08-07

Assigner: GitHub, Inc.

Description

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's namespaces provide multi-tenant separation. A tenant who intentionally leaks lease identifiers can have their lease and underlying credential revoked or renewed by a user in another tenant via the legacy, undocumented `sys/revoke` and `sys/renew` endpoints. This is fixed in OpenBao v2.5.4.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-07
Last Modified
2026-08-07
Generated
2026-08-08
AI Q&A
2026-08-08
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
openbao openbao 2.5.4

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

OpenBao before version 2.5.4 has a namespace separation issue where a tenant leaking lease identifiers can have their lease or credentials revoked or renewed by another tenant using legacy sys/revoke and sys/renew endpoints.

Detection Guidance

Detecting this vulnerability requires checking for unauthorized use of the legacy sys/revoke and sys/renew endpoints in OpenBao. Monitor logs for unusual lease revocation or renewal activities across tenants. Check OpenBao version to confirm if it is below 2.5.4.

Impact Analysis

An attacker in one tenant could revoke or renew leases and credentials of another tenant, leading to unauthorized access or service disruption if they obtain leaked lease IDs.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, potentially violating confidentiality requirements in GDPR and HIPAA, resulting in compliance failures and penalties.

Mitigation Strategies

Upgrade OpenBao to version 2.5.4 or later immediately. Disable or restrict access to the legacy sys/revoke and sys/renew endpoints if they are not required. Review and audit lease identifiers for any signs of misuse or unauthorized access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-45808. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart