OpenBao is an open source identity-based secrets management system. Prior to 2.5.3, when OpenBao's initial namespace deletion fails, subsequent retries fail to properly remove all data before marking the namespace as deleted. This can affect any outstanding leases as well as potentially leaving unrelated storage entries around. This vulnerability is fixed in 2.5.3.
References
| Link | Resource |
|---|---|
| https://github.com/openbao/openbao/commit/6d2e0506e2b41be0eaa6643bf7b4efc9a2c09445 | Patch |
| https://github.com/openbao/openbao/releases/tag/v2.5.3 | Product Release Notes |
| https://github.com/openbao/openbao/security/advisories/GHSA-vv66-6rp4-wr4f | Mitigation Vendor Advisory |
Configurations
History
18 May 2026, 14:10
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:openbao:openbao:*:*:*:*:*:*:*:* | |
| References | () https://github.com/openbao/openbao/commit/6d2e0506e2b41be0eaa6643bf7b4efc9a2c09445 - Patch | |
| References | () https://github.com/openbao/openbao/releases/tag/v2.5.3 - Product, Release Notes | |
| References | () https://github.com/openbao/openbao/security/advisories/GHSA-vv66-6rp4-wr4f - Mitigation, Vendor Advisory | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
| First Time |
Openbao openbao
Openbao |
14 May 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-14 15:16
Updated : 2026-05-18 14:10
NVD link : CVE-2026-42186
Mitre link : CVE-2026-42186
CVE.ORG link : CVE-2026-42186
JSON object : View
Products Affected
openbao
- openbao
CWE
CWE-212
Improper Removal of Sensitive Information Before Storage or Transfer
