Impact
OpenBao's templated access control, PKI, and SSH policies could substitute attacker‑controlled identity data without rejecting syntax‑significant characters. Wildcard characters such as asterisks, pluses, slashes, and commas could broaden policy scopes or grant access to unauthorized resources. The vulnerability allows a malicious actor to elevate privileges, gain unauthorized access, or issue certificates for domains or principals not intended by the policy author, as the flaw is based on CWE‑863.
Affected Systems
The issue affects OpenBao (openbao) deployments using any release prior to 2.6.0. Version 2.6.0 and later include a fix that removes the ability for templates to contain wildcard characters that alter policy semantics.
Risk and Exploitability
The CVSS score of 7.5 indicates a high impact, and the EPSS score is not available, implying no publicly known exploitation yet. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires that the system uses templated policy data that attackers can modify, for example via a user‑supplied identity entity. The likely attack vector is through the API or interface that accepts identity data used in template rendering, though the exact mode is not explicitly documented. Given the severity and the availability of a patch, the risk is high if the vulnerable configurations remain in use.
OpenCVE Enrichment