OpenBao's Token Store Allows Cross-Namespace Renewal, Revocation
Package
Affected versions
< 0.0.0-20260420162526-f58111d2ca54
Patched versions
0.0.0-20260420162526-f58111d2ca54
Description
Published by the National Vulnerability Database
Apr 21, 2026
Published to the GitHub Advisory Database
Apr 21, 2026
Reviewed
Apr 21, 2026
Last updated
Apr 21, 2026
Impact
OpenBao's namespaces provide multi-tenant separation. A tenant who leaks token accessors can have their token revoked or renewed by a privileged administrator in another tenant.
Patches
This was addressed in v2.5.3.
References