CVE-2026-63132

critical

Description

OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, OpenBao's handleLogicalRecovery path in http/logical.go compared the highly privileged recovery token with ordinary string equality. A remote unauthenticated attacker able to make repeated recovery mode requests and measure response timing could infer the recovery token. The recovered token could then authorize recovery mode operations that read or modify OpenBao data. This issue is fixed in version 2.6.0.

References

https://github.com/openbao/openbao/security/advisories/GHSA-34fc-gh42-pj53

https://github.com/openbao/openbao/releases/tag/v2.6.0

https://github.com/openbao/openbao/pull/3472

https://github.com/openbao/openbao/pull/3388

https://github.com/openbao/openbao/commit/763625a2072103ea9e9122f2a8408e0b988d287a

https://github.com/openbao/openbao/commit/0f2d90c331f25d1c6cd108638da03f4c7bd949a8

https://github.com/hashicorp/vault/blob/main/CHANGELOG.md#203

Details

Source: Mitre, NVD

Published: 2026-09-23

Updated: 2026-09-23

Risk Information

CVSS v2

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 7.5

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Severity: High

CVSS v4

Base Score: 9.2

Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Severity: Critical

EPSS

EPSS: 0.00497