CVE-2026-39388General(openbao / openbao)

LOWCVSS 3.1 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch openbao openbao systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, OpenBao's Certificate authentication method, when a token renewal is requested and `disable_binding=true` is set, attempts to verify the current request's presented mTLS certificate matches the original. Token renewals for other authentication methods do not require any supplied login information. Due to incorrect matching, the certificate authentication method would allow renewal of tokens for which the attacker had a sibling certificate+key signed by the same CA, but which did not necessarily match the original role or the originally supplied certificate. This implies an attacker could still authenticate to OpenBao in a similar scope, however, token renewal implies that an attacker may be able to extend the lifetime of dynamic leases held by the original token. This attack requires knowledge of either the original token or its accessor. This vulnerability is original from HashiCorp Vault. This is addressed in v2.5.3. As a workaround, ensure privileged roles are tightly scoped to single certificates.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-295

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openbao

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-21); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
openbao

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-21: 2Mentions · 2026-04-28: 1Patch / Workaround · 2026-04-21: 1Technical Details · 2026-04-21: 2Technical Details · 2026-04-28: 104-2104-28
Signal classification3 categories
General
133.3%
Patch
133.3%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-212
General1Patch1
2026-04-281
Disclosure1
Full discourse3 posts
  • CVE@CVEnew
    Patch

    CVE-2026-39388 OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, OpenBao's Certificate authentication method, when a token renewal is reque… https://www.cve.org/CVERecord?id=CVE-2026-39388

    Post summary

    CVE-2026-39388 affects OpenBao’s Certificate authentication during token renewal and is remedied by upgrading to version 2.5.3; no exploit or PoC is reported, and no active exploitation is noted.

    0001069
    57.2K followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-39388: CVE-2026-39388: Authentication Bypass in OpenBao Certificate Token Renewal OpenBao versions prior to 2.5.3 contain an authentication bypass vulnerability within the Certificate Authentication (auth/cert) method. A flaw in the token ren... https://cvereports.com/reports/CVE-2026-39388

    Post summary

    The report announces an authentication bypass vulnerability in OpenBao’s certificate token renewal feature, specifying affected versions and impacted authentication method but provides no PoC, exploit, or mitigation.

    0000029
    36 followersView on X
  • DailyCVE@dailycve
    General

    🔵 OpenBao, Certificate Authentication Bypass, #CVE-2026-39388 (Low) https://dailycve.com/openbao-certificate-authentication-bypass-cve-2026-39388-low/

    Post summary

    The notice highlights a low‑severity certificate authentication bypass in OpenBao but offers only minimal detail, lacking a PoC, exploit code, or patch information.

    0000025
    183 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenbaoopenbao---

Explore more