CVE-2026-46405Disclosure

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, in OpenBao's Kerberos auth method on the `GET` handler, or when an `Authorization: Negotiate` header is supplied, the response is includes a `logical.Auth` object in addition to an error message. This results in tokens being created with only the default policy, default TTL, and no entity information, which are hidden by the returned error message. No access to these tokens by the caller occurs and the authentication token is not ever made accessible outside of `sys/raw`. This is fixed in OpenBao v2.5.4. As a workaround, users may set a rate limit quota to limit the creation of these paths. As the path is unauthenticated, it isn't possible to deny access to it.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-08-08); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-08-08: 3Mentions · 2026-08-09: 1Patch / Workaround · 2026-08-09: 1Technical Details · 2026-08-09: 108-0808-09
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-083
Disclosure2General1
2026-08-091
Disclosure1
Full discourse4 posts
  • CyberSignal | Cybersecurity News@XQOPTRX
    Disclosure

    🔑 OpenBao Kerberos authentication bug creates unintended tokens CVE-2026-46405 affects OpenBao before 2.5.4. Certain Kerberos authentication requests could cause unintended tokens to be created because authentication data was returned alongside an error path. ✅ Fixed in OpenBao 2.5.4. 🔎 Source: OpenBao / GitHub / CVE #OpenBao #IdentitySecurity #Kerberos #CVE #CyberSecurity

    Post summary

    CVE-2026-46405 is a Kerberos authentication bug in OpenBao that can generate unintended tokens; the vendor has patched it in version 2.5.4, and no exploitation or PoC details are disclosed.

    0000041
    34 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-46405 OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, in OpenBao's Kerberos auth method on the `GET` handler, or when an `Author… https://www.cve.org/CVERecord?id=CVE-2026-46405 ----- Traducción: CVE-2026-46405 Ope… http://infoflow.cloud`

    Post summary

    The post shares a CVE identifier and a brief mention of affected code paths without providing any proof of concept, exploit, or mitigation details, making it a general disclosure.

    0000042
    98 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-46405 OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, in OpenBao's Kerberos auth method on the `GET` handler, or when an `Author… https://www.cve.org/CVERecord?id=CVE-2026-46405

    Post summary

    The passage highlights CVE‑2026‑46405 as affecting OpenBao’s Kerberos auth before v2.5.4, but provides no further technical, exploit, or mitigation details.

    000001.4K
    57.9K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-46405 OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, in OpenBao's Kerberos auth method on the `GET` handler, or when an `Authorization https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-46405

    Post summary

    The text announces a new CVE affecting OpenBao’s Kerberos authentication before version 2.5.4, but lacks further technical or exploit details.

    00000170
    4.1K followersView on X

Explore more