Impact
The vulnerability resides in the lease lookup routing within the OpenBao service. An authenticated user who can access the sys/leases/revoke/:lease_id endpoint in one namespace can also revoke, and in a related issue can renew, leases in a different namespace when the targeted lease identifier is known. This bypasses namespace ACL isolation, giving the attacker the ability to invalidate another tenant’s secret credentials. The weakness is captured as CWE-863. The impact is a limited privilege escalation that could lead to credential compromise or denial of service for affected tenants.
Affected Systems
OpenBao. All releases before version 2.5.5—including 2.5.4 and earlier—are vulnerable. The fix is shipped in release 2.5.5 and later versions. Vendors: openbao:openbao.
Risk and Exploitability
The CVSS score of 2.1 indicates low severity. The EPSS score is < 1%, signifying a low probability of exploitation. The vulnerability is not listed in CISA's KEV catalog. Attacks require legitimate access to the sys/leases/revoke/ or renew endpoint and knowledge of a lease ID from another namespace. An adversary could intentionally disclose or guess a lease identifier and use the endpoint from its own namespace to revoke a tenant’s lease. The exploit is permission‑based rather than code exploitation, which further reduces its likelihood.
OpenCVE Enrichment
Github GHSA