Description
OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, an OpenBao user with access to sys/leases/revoke/:lease_id in one namespace could revoke a lease in another namespace when the foreign lease_id was known, bypassing namespace ACL isolation. The affected lease lookup routing in vault/expiration.go allowed FetchLeaseInfo and loadEntry to resolve cached or stored lease data outside the request namespace, allowing a tenant that intentionally disclosed a lease identifier to have the lease and its underlying credential revoked by another tenant. This issue is fixed in version 2.5.5.
Published: 2026-09-15
Score: 2.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in the lease lookup routing within the OpenBao service. An authenticated user who can access the sys/leases/revoke/:lease_id endpoint in one namespace can also revoke, and in a related issue can renew, leases in a different namespace when the targeted lease identifier is known. This bypasses namespace ACL isolation, giving the attacker the ability to invalidate another tenant’s secret credentials. The weakness is captured as CWE-863. The impact is a limited privilege escalation that could lead to credential compromise or denial of service for affected tenants.

Affected Systems

OpenBao. All releases before version 2.5.5—including 2.5.4 and earlier—are vulnerable. The fix is shipped in release 2.5.5 and later versions. Vendors: openbao:openbao.

Risk and Exploitability

The CVSS score of 2.1 indicates low severity. The EPSS score is < 1%, signifying a low probability of exploitation. The vulnerability is not listed in CISA's KEV catalog. Attacks require legitimate access to the sys/leases/revoke/ or renew endpoint and knowledge of a lease ID from another namespace. An adversary could intentionally disclose or guess a lease identifier and use the endpoint from its own namespace to revoke a tenant’s lease. The exploit is permission‑based rather than code exploitation, which further reduces its likelihood.

Generated by OpenCVE AI on September 20, 2026 at 15:56 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade OpenBao to version 2.5.5 or later.
  • Constraining lease identifier disclosure to trusted users and enforcing strict ACLs on sys/leases/revoke/ and sys/leases/renew/ endpoints.
  • Monitoring audit logs for cross‑namespace lease revocation or renewal events and investigating anomalies.

Generated by OpenCVE AI on September 20, 2026 at 15:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-c36x-h252-g9x2 OpenBao: Cross-namespace lease revocation/renewal via canonical sys/leases/{revoke,renew} — incomplete fix of CVE-2026-45808
History

Tue, 15 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Openbao
Openbao openbao
Vendors & Products Openbao
Openbao openbao

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, an OpenBao user with access to sys/leases/revoke/:lease_id in one namespace could revoke a lease in another namespace when the foreign lease_id was known, bypassing namespace ACL isolation. The affected lease lookup routing in vault/expiration.go allowed FetchLeaseInfo and loadEntry to resolve cached or stored lease data outside the request namespace, allowing a tenant that intentionally disclosed a lease identifier to have the lease and its underlying credential revoked by another tenant. This issue is fixed in version 2.5.5.
Title OpenBao: Cross-namespace lease revocation/renewal via canonical sys/leases/{revoke,renew} — incomplete fix of CVE-2026-45808
Weaknesses CWE-863
References
Metrics cvssV4_0

{'score': 2.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T17:26:45.372Z

Reserved: 2026-06-17T14:40:28.379Z

Link: CVE-2026-55774

cve-icon Vulnrichment

Updated: 2026-09-15T17:26:41.938Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T16:17:15.923

Modified: 2026-09-25T14:23:59.847

Link: CVE-2026-55774

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:00:14Z

Weaknesses