Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Openbao

First CVE: Mar 4, 2024Active for: 2 yearsTotal CVEs: 26
32.7
VTI Score
Medium

OpenBao is a centralized secrets-management and identity platform derived from HashiCorp Vault that addresses credential, encryption-key, and token lifecycle management across infrastructure and cloud environments. The vendor's disclosures, though focused on a narrow product line anchored by OpenBao itself and its AWS plugin, have prominence commensurate with the platform's role in protecting authentication and encryption material at scale. Vulnerabilities affecting the vendor skew toward moderate severity outcomes and recur through weakness classes including sensitive-data logging, improper certificate validation, input-validation gaps, and inadequate authentication-attempt controls—issues that, in a secrets-management context, can expose credentials or undermine the integrity of access policies. Defenders should treat OpenBao updates as a priority for any environment where it serves as a credential or encryption authority, since flaws that compromise the trust boundary of the platform can cascade to every downstream consumer. Current exploitation activity and severity figures are shown alongside this summary.

FAUCET AI Generated
26
Total CVEs
More Total CVEs than 97% of tracked vendors
4.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 97% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 42% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Openbao over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 4, 2024
2 years ago
Most Recent CVE
May 14, 2026
71 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (26 CVEs).

26 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-33757HIGH
OpenBao is an open source identity-based secrets management system. Prior to version 2.5.2, OpenBao does not prompt for user confirmation when logging in via JWT/OIDC and a role wi
Mar 27, 20268.332NONO
CVE-2025-54997CRITICAL
OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 2.3.1 and below, some OpenBao d
Aug 9, 20259.132NONO
CVE-2024-2048CRITICAL
Vault and Vault Enterprise (“Vault”) TLS certificate auth method did not correctly validate client certificates when configured with a non-CA certificate as trusted certificate. In
Mar 4, 20249.830NONO
CVE-2025-59048HIGH
OpenBao's AWS Plugin generates AWS access credentials based on IAM policies. Prior to version 0.1.1, the AWS Plugin is vulnerable to cross-account IAM role Impersonation in the AWS
Oct 23, 20258.127NONO
CVE-2026-42186HIGH
OpenBao is an open source identity-based secrets management system. Prior to 2.5.3, when OpenBao's initial namespace deletion fails, subsequent retries fail to properly remove all
May 14, 20267.526NONO
CVE-2025-59043HIGH
OpenBao is an open source identity-based secrets management system. In OpenBao versions prior to 2.4.1, JSON objects after decoding may use significantly more memory than their ser
Oct 17, 20257.526NONO
CVE-2024-7594HIGH
Vault’s SSH secrets engine did not require the valid_principals list to contain a value by default. If the valid_principals and default_user fields of the SSH secrets engine config
Sep 26, 20248.826NONO
CVE-2025-64761HIGH
OpenBao is an open source identity-based secrets management system. Prior to version 2.4.4, a privileged operator could use the identity group subsystem to add a root policy to a g
Nov 25, 20257.225NONO
CVE-2025-62513HIGH
OpenBao is an open source identity-based secrets management system. In versions 2.2.0 to 2.4.1, OpenBao's audit log experienced a regression wherein raw HTTP bodies used by few end
Oct 22, 20257.525NONO
CVE-2026-33758MEDIUM
OpenBao is an open source identity-based secrets management system. Prior to version 2.5.2, OpenBao installations that have an OIDC/JWT authentication method enabled and a role wit
Mar 27, 20266.124NONO
View all 26 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products26 CVEs
12%
38%
42%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network26 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low24 (92.3%)
High2 (7.7%)
Unknown0 (0.0%)
User Interaction
None19 (73.1%)
Unknown0 (0.0%)
Required7 (26.9%)
Privileges Required
Low4 (15.4%)
High10 (38.5%)
None12 (46.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (26 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Openbao.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Openbao — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Openbao's Products

View all 2 CNAs →

Top CWEs