Record summary

CVE-2026-40264 has a selected CVSS score of 2.0 (low).

Description

OpenBao is an open source identity-based secrets management system. OpenBao's namespaces provide multi-tenant separation. Prior to version 2.5.3, a tenant who leaks token accessors can have their token revoked or renewed by a privileged administrator in another tenant. This is addressed in v2.5.3.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 21, 2026 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE List< 2.5.3affected

github.com/openbao/openbao

Browse Go / github.com/openbao/openbao
GitHub AdvisoryBefore 0.0.0-20260420162526-f58111d2ca54 · Fixed in 0.0.0-20260420162526-f58111d2ca54affected

References

6