PT-2026-33881 · Openbao+2 · Openbao+2

CVE-2026-39388

·

Published

2026-04-20

·

Updated

2026-07-30

CVSS v2.0

3.6

Low

VectorAV:N/AC:H/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions OpenBao versions prior to 2.5.3
Description The Certificate authentication method contains a flaw during token renewal when disable binding=true is configured. The system incorrectly verifies if the mTLS certificate presented during a renewal request matches the original. This allows an attacker with a sibling certificate and key signed by the same Certificate Authority (CA) to renew tokens, even if they do not match the original role or certificate. While the attacker must possess the original token or its accessor, this could allow them to extend the lifetime of dynamic leases. This issue originated from HashiCorp Vault.
Recommendations Update to version 2.5.3. As a temporary workaround, ensure privileged roles are tightly scoped to single certificates.

Exploit

Fix

Incorrect Authorization

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-08725
BIT-OPENBAO-2026-39388
CVE-2026-39388
GHSA-7CCV-RP6M-RFFR
GO-2026-5213
OPENSUSE-SU-2026:10594-1
OPENSUSE-SU-2026:21483-1

Affected Products

Hashicorp Vault
Openbao
Red Os