GHSA-v8v8-cm84-m686High

OpenBao's cross-namespace lease revocation via legacy sys/revoke path bypasses ACL

Published
May 28, 2026
Last Modified
May 28, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

OpenBao's namespaces provide multi-tenant separation. A tenant who intentionally leaks lease identifiers can have their lease and underlying credential revoked or renewed by a user in another tenant via the legacy, undocumented sys/revoke and sys/renew endpoints.

Patch

This will be addressed in v2.5.4.

🎯 Affected products1

  • go/github.com/openbao/openbao:<= 2.5.3

🔗 References (5)