Impact
OpenBao is an open‑source identity‑based secrets management system that, before version 2.5.5, allowed users who had been granted capabilities on the path /sys/namespaces/root within a non‑root namespace to manipulate the system backend's containing namespace. By exploiting how the literal root path is handled during namespace canonicalization, an attacker can cause /sys/namespaces/root to resolve to the system backend’s containing namespace rather than the actual root. This allows the attacker to perform operations—such as lookups, deletions, locking, or modifying custom metadata—against that namespace, provided they hold the necessary capabilities on the path and its subpaths (e.g. /api‑lock). Root or unrelated namespaces are not affected, and the exploit’s effect depends on the specific capabilities granted. The issue was fixed with the 2.5.5 release.
Affected Systems
Vendors affected are OpenBao, version 2.5.4 and earlier, as well as any 2.5.x build prior to v2.5.5. The fix was introduced in release v2.5.5, and subsequent releases such as v2.6.0 also contain the patch. Any deployment running a 2.5.x roll that does not include the 2.5.5 hot‑fix remains vulnerable.
Risk and Exploitability
The CVSS score of 2.3 indicates low severity. The EPSS score is less than 1%, indicating a very low probability of exploitation. The flaw requires the attacker already have capabilities on the /sys/namespaces/root path inside a non‑root namespace, so it is only exploitable where ACLs are misconfigured or permissive. It is not listed in CISA’s KEV catalog, but organizations should still address it promptly to prevent privilege escalation that could compromise sensitive namespaces.
OpenCVE Enrichment
Github GHSA