PT-2026-97131 · Openbao · Openbao
CVE-2026-77285
·
Published
2026-09-22
·
Updated
2026-09-23
CVSS v4.0
2.4
Low
| Vector | AV:L/AC:L/AT:P/PR:H/UI:A/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
OpenBao versions prior to 2.6.0
Description
In the OpenBao Agent's exec rendering mode, secrets defined in the
env template may be written to standard output. This occurs when the system re-creates the template runner following repeated rendering failures, specifically after the num retries limit is reached. A local user, log collector, or process supervisor with access to the output can obtain these rendered secret values.Recommendations
Update to version 2.6.0.
Exploit
Fix
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openbao