PT-2026-96137 · Openbao · Openbao

CVE-2026-71543

·

Published

2026-09-21

·

Updated

2026-09-29

CVSS v4.0

7.5

High

VectorAV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenBao versions prior to 2.6.0
Description Templated ACL, PKI, and SSH policies fail to reject syntax-significant characters when substituting attacker-controlled identity data. In ACL templated policies, characters such as asterisks, plus signs, and slashes can alter path matching. In PKI allowed uri sans template and allowed domains policies, an asterisk can expand certificate issuance to unauthorized domains. In SSH allowed users and allowed domains policies, a comma can be used to add unauthorized principals. This issue can lead to privilege escalation, unauthorized access, and unauthorized certificate issuance. Exploitation is possible when deployments use templated policy data that users can freely modify, though templates based on the randomly generated identity.entity.id value are not affected.
Recommendations Update to version 2.6.0.

Exploit

Fix

LPE

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-OPENBAO-2026-71543
CVE-2026-71543
GHSA-59W7-V8RR-PR4P

Affected Products

Openbao