CVE-2026-33757Disclosure(openbao / openbao)

LOWCVSS 8.3 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch openbao openbao systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.2, OpenBao does not prompt for user confirmation when logging in via JWT/OIDC and a role with `callback_mode` set to `direct`. This allows an attacker to start an authentication request and perform "remote phishing" by having the victim visit the URL and automatically log-in to the session of the attacker. Despite being based on the authorization code flow, the `direct` mode calls back directly to the API and allows an attacker to poll for an OpenBao token until it is issued. Version 2.5.2 includes an additional confirmation screen for `direct` type logins that requires manual user interaction in order to finish the authentication. This issue can be worked around either by removing any roles with `callback_mode=direct` or enforcing confirmation for every session on the token issuer side for the Client ID used by OpenBao.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-384

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openbao

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 2 mentions (2026-03-27); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
openbao

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-27: 2Mentions · 2026-03-28: 1Mentions · 2026-03-30: 1PoC Mentioned / Linked · 2026-03-30: 1Patch / Workaround · 2026-03-27: 1Technical Details · 2026-03-27: 2Technical Details · 2026-03-28: 1Technical Details · 2026-03-30: 103-2703-2803-30
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-272
Disclosure1Patch1
2026-03-281
Disclosure1
2026-03-301
Disclosure1
Full discourse4 posts
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-33757: OpenBao lacks user confirmation ... Silent OIDC token hijacking via callback polling - attackers can remotely phish victims into auto-authenticating to att... https://zerodaysignal.com/vulnerability/CVE-2026-33757 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces the discovery of CVE-2026-33757, describing a silent OIDC token hijacking flaw in OpenBao and linking to a detailed vulnerability page.

    00020113
    227 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-33757: CRITICAL] OpenBao v2.5.2 enhances security by adding user confirmation for direct logins, preventing remote phishing attacks. Update to protect against this vulnerability. #CyberSecurity#cve,CVE-2026-33757,#cybersecurity https://cvefind.com/CVE-2026-33757

    Post summary

    The post announces that OpenBao v2.5.2 addresses CVE‑2026‑33757 by adding user confirmation for direct logins to prevent remote phishing, urging users to update.

    0001051
    617 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-33757 - Critical OpenBao is an open source identity-based secrets management system. Prior to version 2.5.2, OpenBao does not prompt for user confirmation when logging in via JWT/OIDC and a role with `cal... https://www.thehackerwire.com/vulnerability/CVE-2026-33757/ https://t.co/kFCxOIWYSG

    Post summary

    The post announces a critical CVE affecting OpenBao’s authentication flow, providing technical insights into the issue without mentioning PoC code, exploits, active attacks, or patches.

    0000045
    163 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    `OpenBao` lacks user confirmation for OIDC direct callback, potentially enabling authentication bypass (CVE-2026-33757). Review your OIDC configurations. #OpenBao #OIDC #infosec https://www.pulsepatch.io/posts/cve-2026-33757-openbao-oidc-lack-user-confirmation

    Post summary

    The tweet announces a new authentication bypass flaw (CVE‑2026‑33757) in OpenBao's OIDC direct callback, warning users to review configurations.

    0000032
    6 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenbaoopenbao---

Explore more