What is CVE-2026-45808?
A critical isolation vulnerability in OpenBao prior to version 2.5.4 allows a tenant in a multi-tenant namespace environment to revoke or renew credentials of another tenant by exploiting intentionally leaked lease identifiers. Immediate update to version 2.5.4 is strongly recommended to prevent unauthorized secret management.
Azərbaycanca: OpenBao-nun 2.5.4 öncəsi versiyalarında, çoxkirayəli mühitlərdə ad fəzaları (namespaces) arasında bir kirayəçinin bilərəkdən sızdırdığı lease identifikatorları vasitəsilə, başqa bir kirayəçinin onun kredensiallarını ləğv edə və ya yeniləyə biləcəyi kritik təcrid zəifliyi aşkarlanıb. Bu, məxfi məlumatların icazəsiz idarə olunmasına yol aça bildiyi üçün dərhal 2.5.4 versiyasına yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
How can a tenant manage another tenant's credentials in a multi-tenant OpenBao environment?
An attacker can revoke or renew another tenant's credentials by exploiting intentionally leaked lease identifiers to bypass namespace isolation.
What measure should be taken to protect against CVE-2026-45808?
OpenBao should be immediately updated to version 2.5.4.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.