PT-2026-28530 · Openbao+1 · Openbao+1

·

CVE-2026-33758

·

Publicado

2026-03-25

·

Atualizado

2026-07-30

CVSS v3.1

9.6

Crítica

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions OpenBao versions prior to 2.5.2
Description OpenBao, an open source identity-based secrets management system, is susceptible to Reflected Cross-Site Scripting (XSS) through the error description parameter during failed authentication attempts when an OIDC/JWT authentication method is enabled and a role is configured with callback mode=direct. This allows an attacker to gain access to the token used in the Web UI by a victim. The issue is addressed by replacing the error description parameter with a static error message. The API endpoint involved in the vulnerability is not explicitly mentioned. The vulnerable parameter is error description.
Recommendations Versions prior to 2.5.2 should be updated to version 2.5.2 or later. As a mitigation, remove any roles with callback mode set to direct.

Exploit

Correção

DoS

Improper Encoding or Escaping of Output

RCE

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-08726
BIT-OPENBAO-2026-33758
CVE-2026-33758
GHSA-CPJ3-3R2F-XJ59
GO-2026-4862
OPENSUSE-SU-2026:10438-1
OPENSUSE-SU-2026:21483-1
SUSE-SU-2026:1135-1

Produtos afetados

Openbao
Red Os