Description
OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, OpenBao used EscapeLDAPValue, an RFC 4514 distinguished-name escaping function, where RFC 4515 LDAP search-filter escaping was required in sdk/helper/ldaputil/client.go GetUserDN. With the LDAP authentication backend configured for an Active Directory UPNDomain path or UserDN and UserAttr binding, an attacker-controlled username containing filter metacharacters could alter the search predicate and select a different directory entry because EscapeLDAPValue does not neutralize the characters handled by ldap.EscapeFilter. A resulting token could be associated with another LDAP identity and gain access to secrets, policies, or modification capabilities assigned to that identity. This issue is fixed in version 2.5.5.
Published: 2026-09-15
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authorization bypass via LDAP injection
Action: Patch
AI Analysis

Impact

OpenBao is an open source identity‑based secrets management system. Prior to version 2.5.5, OpenBao uses the RFC 4514 EscapeLDAPValue function to build LDAP search filters, although RFC 4515 LDAP search‑filter escaping is required in the GetUserDN helper. When the LDAP authentication backend is configured for an Active Directory UPNDomain path, or with UserDN and UserAttr bindings, a malicious username containing LDAP filter metacharacters can alter the search predicate and select a different directory entry because EscapeLDAPValue does not neutralize the characters handled by ldap.EscapeFilter. The resulting authentication token becomes associated with another LDAP identity, granting the attacker access to secrets, policies, or modification capabilities tied to that identity. The vulnerability is fixed in OpenBao 2.5.5.

Affected Systems

OpenBao versions prior to 2.5.5, including all 1.x and 2.x releases, are affected when the LDAP authentication backend is configured with an Active Directory UPNDomain path, or with UserDN or UserAttr bindings. Any deployment that relies on LDAP for user lookup in these configurations is vulnerable.

Risk and Exploitability

The CVSS score of 6.8 indicates a moderate severity. The EPSS score is less than 1%, indicating a very low exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. The attack vector requires an attacker to supply a malicious username to the LDAP authentication endpoint, so the exploit can be performed over the network if that interface is reachable. Successful exploitation results in a valid authentication token that maps to an unintended LDAP identity, thereby granting the attacker the permissions assigned to that identity.

Generated by OpenCVE AI on September 20, 2026 at 16:13 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade OpenBao to version 2.5.5 or newer, which replaces EscapeLDAPValue with proper filter escaping.
  • If a prompt upgrade is not possible, restrict the LDAP authentication endpoint to trusted hosts or network segments so that only legitimate clients can attempt authentication.
  • Validate or sanitize usernames on the server side to remove LDAP filter metacharacters or enforce a whitelist of acceptable characters before constructing the search filter, ensuring that only intended directory entries can be returned.

Generated by OpenCVE AI on September 20, 2026 at 16:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-6mwx-4547-5vc9 OpenBao: LDAPi ldaputil (wrong escape func)
History

Fri, 18 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Openbao
Openbao openbao
Vendors & Products Openbao
Openbao openbao

Tue, 15 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, OpenBao used EscapeLDAPValue, an RFC 4514 distinguished-name escaping function, where RFC 4515 LDAP search-filter escaping was required in sdk/helper/ldaputil/client.go GetUserDN. With the LDAP authentication backend configured for an Active Directory UPNDomain path or UserDN and UserAttr binding, an attacker-controlled username containing filter metacharacters could alter the search predicate and select a different directory entry because EscapeLDAPValue does not neutralize the characters handled by ldap.EscapeFilter. A resulting token could be associated with another LDAP identity and gain access to secrets, policies, or modification capabilities assigned to that identity. This issue is fixed in version 2.5.5.
Title OpenBao: LDAPi ldaputil (wrong escape func)
Weaknesses CWE-90
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T11:59:03.495Z

Reserved: 2026-06-17T14:34:51.881Z

Link: CVE-2026-55770

cve-icon Vulnrichment

Updated: 2026-09-15T16:41:26.831Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T16:17:15.763

Modified: 2026-09-29T19:06:32.333

Link: CVE-2026-55770

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:15:18Z

Weaknesses
  • CWE-90

    Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')