PT-2026-97129 · Openbao · Openbao

CVE-2026-63132

·

Published

2026-09-22

·

Updated

2026-09-23

CVSS v4.0

9.2

Critical

VectorAV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenBao versions prior to 2.6.0
Description OpenBao is an identity-based secrets management system. The handleLogicalRecovery function in the http/logical.go file uses ordinary string equality to compare the highly privileged recovery token. A remote unauthenticated attacker can perform a timing attack—a method of inferring secret data by measuring the time a system takes to respond to different inputs—by making repeated recovery mode requests. This allows the attacker to infer the recovery token and authorize operations to read or modify data within the system.
Recommendations Update to version 2.6.0.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63132
GHSA-34FC-GH42-PJ53

Affected Products

Openbao