CVE-2026-46358
Received Received - Intake

OpenBao Audit Log Header Redaction Flaw Exposes Auth Data

Vulnerability report for CVE-2026-46358, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-07

Last updated on: 2026-08-07

Assigner: GitHub, Inc.

Description

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's inline auth functionality incorrectly redacted audit log entries, resulting in non-auth headers being removed and auth-related headers being retained in cleartext. This requires an attacker to compromise access to the audit device. Operators should review leaked source authentication material and rotate it as appropriate. This is fixed in OpenBao v2.5.4.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-07
Last Modified
2026-08-07
Generated
2026-08-08
AI Q&A
2026-08-08
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
openbao openbao 2.5.4

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-532 The product writes sensitive information to a log file.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

OpenBao before version 2.5.4 has a flaw in its inline auth functionality where audit logs incorrectly redact sensitive information. Non-auth headers are removed while auth-related headers remain in cleartext, potentially exposing authentication material.

Detection Guidance

Review OpenBao audit logs for improperly redacted authentication headers. Check for any cleartext exposure of auth-related headers in logs. Compare log entries against expected redaction behavior in versions prior to 2.5.4.

Impact Analysis

If an attacker gains access to the audit device, they could extract leaked authentication material from the logs. This could allow unauthorized access to secrets managed by OpenBao, leading to data breaches or system compromise.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating confidentiality requirements in GDPR and HIPAA. Exposure of authentication material and secrets may result in non-compliance with data protection regulations.

Mitigation Strategies

Upgrade to OpenBao v2.5.4 or later. Review and rotate any potentially exposed authentication material. Ensure audit logs are properly configured to redact sensitive headers.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-46358. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart