CVE-2026-71543
OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, templated ACL, PKI, and SSH policies could substitute attacker-controlled identity data without rejecting syntax-significant characters. In ACL templated policies, asterisks, plus signs, and slashes could alter path matching. In PKI allowed_uri_sans_template and allowed_domains policies, an asterisk could broaden certificate issuance to unauthorized domains. In SSH allowed_users and allowed_domains policies, a comma could add unauthorized principals. Exploitation requires a deployment to use templated policy data that users can freely modify; templates based on the randomly generated identity.entity.id value are not affected. This could allow privilege escalation, unauthorized access, and unauthorized certificate issuance. This issue is fixed in version 2.6.0.
Not on KEV
Not in CISA's Known Exploited Vulnerabilities catalogue as of the last daily pull. Absence is not proof of safety.
0%
Chance of exploitation in the next 30 days, 17th percentile of all CVEs. A forecast; KEV outranks it.
—
no vector published
—
No exposure census on this CVE's dispatches.
- nvd.nist.gov ↗
- first.org · EPSS ↗
- github.com/hashicorp/vault/blob/main/CHANGELOG.md#201 ↗
- github.com/openbao/openbao/commit/2d4ebafec5c524408b3d4ac1198df909cb7ac8c1 ↗
- github.com/openbao/openbao/commit/e516ce508e1481504cadbfbf62052364339093bc ↗
- github.com/openbao/openbao/pull/3401 ↗
- github.com/openbao/openbao/pull/3473 ↗
Watch this one?
Early access opens alerts first — one email when a CVE you follow lands on KEV or an adversary you follow lands on the wire. Nothing else, ever.