What is CVE-2026-46405?
CVE-2026-46405 is an information disclosure vulnerability in OpenBao's Kerberos auth method prior to version 2.5.4. When handling `GET` requests, the response may expose sensitive `logical.Auth` data alongside error messages. Users should upgrade to the latest version to mitigate this issue.
Azərbaycanca: CVE-2026-46405, OpenBao-nun 2.5.4 öncəsi versiyalarında Kerberos auth metodu ilə bağlı bir sızma zəifliyidir. `GET` sorğuları zamanı səhv mesajı ilə birlikdə həssas `logical.Auth` məlumatları ifşa oluna bilər. OpenBao istifadəçiləri ən son versiyaya yüksəlməklə bu problemi aradan qaldırmalıdır.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Which authentication method in OpenBao is affected by CVE-2026-46405?
CVE-2026-46405 affects the Kerberos auth method in OpenBao.
What type of sensitive data can be exposed when CVE-2026-46405 is exploited?
When exploited, sensitive `logical.Auth` data may be exposed alongside error messages in response to `GET` requests.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.