CVE-2025-54996Disclosure(openbao / openbao)

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 2.3.1 and below, accounts with access to highly-privileged identity entity systems in root namespaces were able to increase their scope directly to the root policy. While the identity system allowed adding arbitrary policies, which in turn could contain capability grants on arbitrary paths, the root policy was restricted to manual generation using unseal or recovery key shares. The global root policy was not accessible from child namespaces. This issue is fixed in version 2.3.2. To workaround this vulnerability, use of denied_parameters in any policy which has access to the affected identity endpoints (on identity entities) may be sufficient to prohibit this type of attack.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openbao

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
openbao

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-06-20: 1Technical Details · 2026-06-20: 106-20
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
Full discourse1 post
  • DailyCVE@dailycve
    Disclosure

    🔴 OpenBao, Privilege Escalation via Namespace Path Canonicalization, #CVE-2025-54996 (High) -DC-Jun2026-518 https://dailycve.com/openbao-privilege-escalation-via-namespace-path-canonicalization-cve-2025-54996-high-dc-jun2026-518/

    Post summary

    The post announces CVE‑2025‑54996, a high‑severity privilege‑escalation flaw in OpenBao, but does not provide PoC, exploit, active-use, or patch details.

    0000045
    215 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenbaoopenbao---

Explore more