PT-2026-51110 · Openbao+1 · Openbao+1
CVE-2026-55775
·
Published
2026-06-19
·
Updated
2026-09-02
CVSS v4.0
2.3
Low
| Vector | AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenBao versions prior to 2.5.5
Description
Users granted namespace management capabilities within a non-root namespace can abuse the canonicalization of the literal path "root" to manage the containing namespace itself. Several endpoints under
/sys/namespaces/* accept a namespace path segment that is canonicalized and appended to the sys mount's containing namespace path. Because the path "root" canonicalizes to an empty string and Access Control Lists (ACLs) are evaluated before this process, a user with permissions for /sys/namespaces/root can perform unauthorized operations on the parent namespace. Depending on the granted capabilities, this allows for looking up, deleting, locking, or patching custom metadata of the containing namespace. The root namespace is immutable and remains unaffected.Recommendations
Update to version 2.5.5.
Fix
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openbao
Red Os