OpenBao is a centralized secrets-management and identity platform derived from HashiCorp Vault that addresses credential, encryption-key, and token lifecycle management across infrastructure and cloud environments. The vendor's disclosures, though focused on a narrow product line anchored by OpenBao itself and its AWS plugin, have prominence commensurate with the platform's role in protecting authentication and encryption material at scale. Vulnerabilities affecting the vendor skew toward moderate severity outcomes and recur through weakness classes including sensitive-data logging, improper certificate validation, input-validation gaps, and inadequate authentication-attempt controls—issues that, in a secrets-management context, can expose credentials or undermine the integrity of access policies. Defenders should treat OpenBao updates as a priority for any environment where it serves as a credential or encryption authority, since flaws that compromise the trust boundary of the platform can cascade to every downstream consumer. Current exploitation activity and severity figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openbao over time
Signals from CVEs in this vendor scope (26 CVEs).
26 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-33757HIGH OpenBao is an open source identity-based secrets management system. Prior to version 2.5.2, OpenBao does not prompt for user confirmation when logging in via JWT/OIDC and a role wi | Mar 27, 2026 | 8.3 | 32 | NO | NO |
CVE-2025-54997CRITICAL OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 2.3.1 and below, some OpenBao d | Aug 9, 2025 | 9.1 | 32 | NO | NO |
CVE-2024-2048CRITICAL Vault and Vault Enterprise (“Vault”) TLS certificate auth method did not correctly validate client certificates when configured with a non-CA certificate as trusted certificate. In | Mar 4, 2024 | 9.8 | 30 | NO | NO |
CVE-2025-59048HIGH OpenBao's AWS Plugin generates AWS access credentials based on IAM policies. Prior to version 0.1.1, the AWS Plugin is vulnerable to cross-account IAM role Impersonation in the AWS | Oct 23, 2025 | 8.1 | 27 | NO | NO |
CVE-2026-42186HIGH OpenBao is an open source identity-based secrets management system. Prior to 2.5.3, when OpenBao's initial namespace deletion fails, subsequent retries fail to properly remove all | May 14, 2026 | 7.5 | 26 | NO | NO |
CVE-2025-59043HIGH OpenBao is an open source identity-based secrets management system. In OpenBao versions prior to 2.4.1, JSON objects after decoding may use significantly more memory than their ser | Oct 17, 2025 | 7.5 | 26 | NO | NO |
CVE-2024-7594HIGH Vault’s SSH secrets engine did not require the valid_principals list to contain a value by default. If the valid_principals and default_user fields of the SSH secrets engine config | Sep 26, 2024 | 8.8 | 26 | NO | NO |
CVE-2025-64761HIGH OpenBao is an open source identity-based secrets management system. Prior to version 2.4.4, a privileged operator could use the identity group subsystem to add a root policy to a g | Nov 25, 2025 | 7.2 | 25 | NO | NO |
CVE-2025-62513HIGH OpenBao is an open source identity-based secrets management system. In versions 2.2.0 to 2.4.1, OpenBao's audit log experienced a regression wherein raw HTTP bodies used by few end | Oct 22, 2025 | 7.5 | 25 | NO | NO |
CVE-2026-33758MEDIUM OpenBao is an open source identity-based secrets management system. Prior to version 2.5.2, OpenBao installations that have an OIDC/JWT authentication method enabled and a role wit | Mar 27, 2026 | 6.1 | 24 | NO | NO |
Signals from CVEs in this vendor scope (26 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openbao.
Media articles that mention a CVE ID that affects a product developed by Openbao — matched by CVE ID, not by vendor name.