Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-40264

16
FAUCET Score

OVERVIEW CVE-2026-40264 is a multi-tenancy isolation vulnerability affecting OpenBao, an open source identity-based secrets management system. Prior to version 2.5.3, the namespace isolation mechanism fails to prevent cross-tenant token manipulation, allowing a privileged administrator in one tenant to revoke or renew tokens belonging to users in other tenants if the token accessor is disclosed. SEVERITY While the CVSS vector is not available, the vulnerability requires privileged administrator access in one tenant combined with knowledge of a token accessor from another tenant, indicating moderate attack complexity. The impact is limited to token lifecycle management (revocation and renewal) rather than unauthorized access to secrets themselves. The FAUCET Risk Score of 32.0/100 reflects low to moderate severity, and the EPSS score of 0.00036 indicates minimal likelihood of widespread exploitation. EXPLOITATION STATUS There is no evidence of active exploitation. The vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog and does not appear on any active hot lists. No public exploit code is known to be available. The issue has been addressed in version 2.5.3, and organizations should prioritize patching as part of routine maintenance rather than as an emergency response.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.5.3CPE matchmatch criteria
cpe:2.3:a:openbao:openbao:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

2.0LOW

CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
PRESENT
Privileges Required
HIGH
User Interaction
PASSIVE
VS Confidentiality
NONE
VS Integrity
NONE
VS Availability
LOW
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.30%
Probability of exploitation in next 30 days
EPSS Percentile
22.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0030 is in the 35th percentile among its peer group of 709 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

gopatch availablevia ghsa
Product: github.com/openbao/openbaoFixed in: 0.0.0-20260420162526-f58111d2ca54
github_advisoryvendor investigatingvia nvd_reference
View patch

Vendor Advisories (1)

goGHSA-p49j-v9wc-wg57low

OpenBao's Token Store Allows Cross-Namespace Renewal, Revocation

Apr 21, 2026

References

github.com / openbao/openbao/security/advisories/GHSA-p49j-v9wc-wg57
Vendor Advisory