OpenBao is an open source identity-based secrets management system. OpenBao's namespaces provide multi-tenant separation. Prior to version 2.5.3, a tenant who leaks token accessors can have their token revoked or renewed by a privileged administrator in another tenant. This is addressed in v2.5.3.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 21 Apr 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenBao is an open source identity-based secrets management system. OpenBao's namespaces provide multi-tenant separation. Prior to version 2.5.3, a tenant who leaks token accessors can have their token revoked or renewed by a privileged administrator in another tenant. This is addressed in v2.5.3. | |
| Title | OpenBao's Token Store Allows Cross-Namespace Renewal, Revocation | |
| Weaknesses | CWE-1259 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-21T00:47:38.156Z
Reserved: 2026-04-10T17:31:45.787Z
Link: CVE-2026-40264
No data.
Status : Received
Published: 2026-04-21T01:16:06.917
Modified: 2026-04-21T01:16:06.917
Link: CVE-2026-40264
No data.
OpenCVE Enrichment
No data.
Weaknesses