CVE-2026-40264General(openbao / openbao)

LOWCVSS 2.7 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch openbao openbao systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenBao is an open source identity-based secrets management system. OpenBao's namespaces provide multi-tenant separation. Prior to version 2.5.3, a tenant who leaks token accessors can have their token revoked or renewed by a privileged administrator in another tenant. This is addressed in v2.5.3.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1259

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openbao

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-21); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
openbao

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-21: 2Mentions · 2026-04-28: 1Patch / Workaround · 2026-04-21: 1Technical Details · 2026-04-28: 104-2104-28
Signal classification2 categories
General
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-212
General1Patch1
2026-04-281
General1
Full discourse3 posts
  • cvereports@_cvereports
    General

    CVE-2026-40264: CVE-2026-40264: Cross-Namespace Boundary Bypass via Token Accessor in OpenBao OpenBao versions prior to 2.5.3 contain an improper namespace context switching vulnerability. An authenticated attacker with administrative privileges in on... https://cvereports.com/reports/CVE-2026-40264

    Post summary

    The report notes a namespace switching flaw in OpenBao versions before 2.5.3, providing technical details but lacking PoC, exploitation evidence, or patch information.

    0000026
    36 followersView on X
  • DailyCVE@dailycve
    General

    🔵 OpenBao, Token Store Cross-Namespace Renewal/Revocation, #CVE-2026-40264 (Low) https://dailycve.com/openbao-token-store-cross-namespace-renewal-revocation-cve-2026-40264-low/

    Post summary

    The text only lists the CVE identifier and provides a link to an external article, offering no substantive detail on exploitation, patching, or technical specifics.

    0000035
    183 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-40264 OpenBao is an open source identity-based secrets management system. OpenBao's namespaces provide multi-tenant separation. Prior to version 2.5.3, a tenant who leaks t… https://www.cve.org/CVERecord?id=CVE-2026-40264

    Post summary

    CVE‑2026‑40264 impacts OpenBao’s tenant namespace separation, and the issue is addressed in version 2.5.3, so users are advised to upgrade.

    0000088
    57.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenbaoopenbao---

Explore more