
🔑 OpenBao Kerberos authentication bug creates unintended tokens CVE-2026-46405 affects OpenBao before 2.5.4. Certain Kerberos authentication requests could cause unintended tokens to be created because authentication data was returned alongside an error path. ✅ Fixed in OpenBao 2.5.4. 🔎 Source: OpenBao / GitHub / CVE #OpenBao #IdentitySecurity #Kerberos #CVE #CyberSecurity
Post summary
CVE-2026-46405 is a Kerberos authentication bug in OpenBao that can generate unintended tokens; the vendor has patched it in version 2.5.4, and no exploitation or PoC details are disclosed.



