CVE-2026-33758Disclosure(openbao / openbao)

LOWCVSS 6.1 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch openbao openbao systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.2, OpenBao installations that have an OIDC/JWT authentication method enabled and a role with `callback_mode=direct` configured are vulnerable to XSS via the `error_description` parameter on the page for a failed authentication. This allows an attacker access to the token used in the Web UI by a victim. The `error_description` parameter has been replaced with a static error message in v2.5.2. The vulnerability can be mitigated by removing any roles with `callback_mode` set to `direct`.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-79CWE-116

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openbao

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
openbao

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-27: 2Patch / Workaround · 2026-03-27: 1Technical Details · 2026-03-27: 203-27
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-33758: OpenBao has Reflected XSS in its... Reflected XSS in OIDC auth flow = direct token theft from OpenBao Web UI - patch immediately or disable `callback_mode=... https://zerodaysignal.com/vulnerability/CVE-2026-33758 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces a Reflected XSS vulnerability (CVE-2026-33758) in OpenBao’s OIDC authentication flow that allows token theft. It urges users to apply the patch immediately or disable the vulnerable callback mode feature.

    0000069
    194 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    `OpenBao` is vulnerable to Reflected XSS (CVE-2026-33758) via OIDC authentication error messages. This can lead to client-side script execution. Monitor for updates. #OpenBao #XSS #infosec https://www.pulsepatch.io/posts/cve-2026-33758-openbao-reflected-xss

    Post summary

    The tweet announces a Reflected XSS vulnerability in OpenBao (CVE‑2026‑33758) via OIDC error messages, noting potential client‑side script execution but provides no PoC, exploit code, or patch information.

    0000036
    6 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenbaoopenbao---

Explore more