PT-2026-97131 · Openbao · Openbao

CVE-2026-77285

·

Published

2026-09-22

·

Updated

2026-09-23

CVSS v4.0

2.4

Low

VectorAV:L/AC:L/AT:P/PR:H/UI:A/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions OpenBao versions prior to 2.6.0
Description In the OpenBao Agent's exec rendering mode, secrets defined in the env template may be written to standard output. This occurs when the system re-creates the template runner following repeated rendering failures, specifically after the num retries limit is reached. A local user, log collector, or process supervisor with access to the output can obtain these rendered secret values.
Recommendations Update to version 2.6.0.

Exploit

Fix

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77285
GHSA-444V-8VXR-P36H

Affected Products

Openbao