CVE-2026-46358 Details
Description
OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's inline auth functionality incorrectly redacted audit log entries, resulting in non-auth headers being removed and auth-related headers being retained in cleartext. This requires an attacker to compromise access to the audit device. Operators should review leaked source authentication material and rotate it as appropriate. This is fixed in OpenBao v2.5.4.
A vulnerability exists in OpenBao's inline authentication feature, where audit log entries are improperly redacted. This issue allows non-authentication headers to be removed while leaving authentication-related headers exposed in cleartext. The vulnerability is present in OpenBao versions through 2.5.3. Exploitation requires access to the audit device, where the unredacted headers can be accessed. Operators are advised to review any exposed authentication information and rotate it as necessary.
Users can upgrade to OpenBao version 2.5.4 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 7, 2026CISA-ADP
Assessed Aug 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/openbao/openbao/issues/3074 | CISA-ADP | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/openbao/openbao/commit/131c6966af4dfb4e1906703436eecdb8f2a3e9df | [email protected] | Source CodeVendor |
| https://github.com/openbao/openbao/issues/3074 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/openbao/openbao/pull/3076 | [email protected] | Issue TrackingVendor |
| https://github.com/openbao/openbao/releases/tag/v2.5.4 | [email protected] | Release NotesVendor |
| https://github.com/openbao/openbao/security/advisories/GHSA-q8cj-789h-vg24 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-532 | Insertion of Sensitive Information into Log File | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| OpenBao | <= 2.5.3 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 11, 2026 | CVE Modified | CISA-ADP |
| Aug 7, 2026 | New CVE Received | [email protected] |
Volerion