EXECUTIVE SUMMARY:
Three vulnerabilities in github.com/openbao/openbao affect policy authorization and recovery mode token handling. The vulnerabilities allow privilege escalation through wildcard or special characters in templated ACL PKI or SSH policies can bypass stricter deny policies for certain LIST operations and can expose the recovery token through a timing attack when OpenBao operates in recovery mode potentially enabling unauthorized access to protected data.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
Three vulnerabilities in github.com/openbao/openbao affect policy authorization and recovery mode token handling. The vulnerabilities allow privilege escalation through wildcard or special characters in templated ACL PKI or SSH policies can bypass stricter deny policies for certain LIST operations and can expose the recovery token through a timing attack when OpenBao operates in recovery mode potentially enabling unauthorized access to protected data.[emaillocker id="1283"]
CVE-2026-71543 (CVSS 7.5 — High): OpenBao's Templated Policies allow privilege escalation via wildcard characters in ACL policies, PKI secrets engine allowed_uri_sans_template and allowed_domains polices, and SSH secrets engine allowed_users and allowed_domains polices.
CVE-2026-63132 (CVSS 9.1 — Critical): OpenBao's Recovery Mode is vulnerable to token leakage via timing attack when running in highly privileged recovery mode.
CVE-2026-63131 (CVSS 6.0 — Medium): OpenBao incorrectly allows certain LIST operations when a broader list permission overrides a stricter deny policy on a trailing wildcard path.
RECOMMENDATIONS:
REFERENCES:
The following reports contain further technical details:
https://github.com/advisories/GHSA-59w7-v8rr-pr4p
https://github.com/advisories/GHSA-34fc-gh42-pj53
https://github.com/advisories/GHSA-xp3c-3jw3-4vcr