Bug 2538817 (CVE-2026-71543)
| Summary: | CVE-2026-71543 openbao: OpenBao: Privilege Escalation via Wildcard Characters in Templated Policies | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | Keywords: | Security |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in OpenBao, an open-source identity-based secrets management system. Templated Access Control List (ACL), Public Key Infrastructure (PKI), and Secure Shell (SSH) policies could substitute attacker-controlled identity data without properly rejecting syntax-significant characters. This vulnerability allows an attacker to use characters such as asterisks, plus signs, slashes, and commas to alter path matching, broaden certificate issuance to unauthorized domains, or add unauthorized principals. Exploitation requires a deployment where users can freely modify templated policy data, potentially leading to privilege escalation, unauthorized access, or unauthorized certificate issuance.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2026-09-22 20:46:32 UTC
|