What is CVE-2026-46358?
CVE-2026-46358 describes a flaw in OpenBao's audit log redaction process. In versions prior to 2.5.4, the inline auth functionality incorrectly removes non-auth headers while retaining auth-related headers in cleartext, potentially exposing sensitive authentication data if an attacker compromises the audit logs, making an immediate upgrade to version 2.5.4 essential.
Azərbaycanca: CVE-2026-46358 OpenBao-nun audit log sistemindəki qüsuru təsvir edir. 2.5.4-dən əvvəlki versiyalarda inline auth funksionallığı audit jurnallarını səhv redaktə edərək, auth ilə əlaqəli olmayan başlıqları silir, lakin autentifikasiya başlıqlarını açıq mətndə saxlayır. Bu zəiflik təcavüzkarın audit loglarına giriş əldə etməsi halında həssas autentifikasiya məlumatlarını ifşa edə bilər, ona görə də dərhal 2.5.4 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Which versions of OpenBao are affected by CVE-2026-46358?
This vulnerability affects OpenBao versions prior to 2.5.4.
If an attacker gains access to audit logs, what type of data does CVE-2026-46358 expose?
If an attacker compromises the audit logs, sensitive authentication data can be exposed because auth-related headers are retained in cleartext.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.