PT-2026-28529 · Openbao+1 · Openbao+1

·

CVE-2026-33757

·

Published

2026-03-25

·

Updated

2026-07-31

CVSS v2.0

9.7

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:P
Name of the Vulnerable Software and Affected Versions OpenBao versions prior to 2.5.2
Description A flaw in the JWT/OIDC authentication method occurs when a role is configured with the callback mode variable set to direct. In this configuration, the system fails to prompt for user confirmation during login. An attacker can initiate an authentication request and perform a remote phishing attack by tricking an authenticated user into visiting a crafted URL, which automatically logs the user into the attacker's session. Although based on the authorization code flow, the direct mode calls back directly to the API, allowing an attacker to poll for an OpenBao token until it is issued.
Recommendations Update to version 2.5.2. Remove any roles configured with callback mode=direct. Enforce confirmation for every session on the token issuer side for the Client ID used by OpenBao.

Exploit

Fix

Session Fixation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-08727
BIT-OPENBAO-2026-33757
CVE-2026-33757
GHSA-7Q7G-X6VG-XPC3
GO-2026-4860
OPENSUSE-SU-2026:10438-1
OPENSUSE-SU-2026:21483-1
SUSE-SU-2026:1135-1

Affected Products

Openbao
Red Os