
🚨 CVE-2026-33758: OpenBao has Reflected XSS in its... Reflected XSS in OIDC auth flow = direct token theft from OpenBao Web UI - patch immediately or disable `callback_mode=... https://zerodaysignal.com/vulnerability/CVE-2026-33758 #netsec #vulnerability #CVE #sysadmin #zeroday
Post summary
The tweet announces a Reflected XSS vulnerability (CVE-2026-33758) in OpenBao’s OIDC authentication flow that allows token theft. It urges users to apply the patch immediately or disable the vulnerable callback mode feature.

