OVERVIEW CVE-2026-40264 is a multi-tenancy isolation vulnerability affecting OpenBao, an open source identity-based secrets management system. Prior to version 2.5.3, the namespace isolation mechanism fails to prevent cross-tenant token manipulation, allowing a privileged administrator in one tenant to revoke or renew tokens belonging to users in other tenants if the token accessor is disclosed. SEVERITY While the CVSS vector is not available, the vulnerability requires privileged administrator access in one tenant combined with knowledge of a token accessor from another tenant, indicating moderate attack complexity. The impact is limited to token lifecycle management (revocation and renewal) rather than unauthorized access to secrets themselves. The FAUCET Risk Score of 32.0/100 reflects low to moderate severity, and the EPSS score of 0.00036 indicates minimal likelihood of widespread exploitation. EXPLOITATION STATUS There is no evidence of active exploitation. The vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog and does not appear on any active hot lists. No public exploit code is known to be available. The issue has been addressed in version 2.5.3, and organizations should prioritize patching as part of routine maintenance rather than as an emergency response.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.5.3CPE matchmatch criteria | cpe:2.3:a:openbao:openbao:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.