Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.2
CVE-2026-63132: OpenBao can leak recovery token through timing
CVE-2026-63132 · published 5 days ago
Summary
OpenBao versions before 2.6.0 let an unauthenticated user measure how long the system responds to recovery requests. By doing this repeatedly, an attacker could figure out the secret recovery token and then gain access to sensitive data or change settings. Upgrade to version 2.6.0 or later to stop this behavior.
What to do
- Update openbao github.com/openbao/openbao to version 0.0.0-20260713141742-763625a20721.
- Update github.com openbao to version 0.0.0-20260713141742-763625a20721.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Go | openbao | github.com/openbao/openbao |
< 0.0.0-20260713141742-763625a20721 >= 0.1.0, <= 1.1.5 Fix: upgrade to 0.0.0-20260713141742-763625a20721
|
| go | github.com | openbao |
< 0.0.0-20260713141742-763625a20721 >= 0.1.0, <= 1.1.5 Fix: upgrade to 0.0.0-20260713141742-763625a20721
|
| – | openbao | openbao | < 2.6.0 |
Original advisory text
OpenBao's Recovery Mode Vulnerable To Token Leakage via Timing Attack
OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, OpenBao's handleLogicalRecovery path in http/logical.go compared the highly privileged recovery token with ordinary string equality. A remote unauthenticated attacker able to make repeated recovery mode requests and measure response timing could infer the recovery token. The recovered token could then authorize recovery mode operations that read or modify OpenBao data. This issue is fixed in version 2.6.0.
References
- https://github.com/openbao/openbao/security/advisories/GHSA-34fc-gh42-pj53
- https://github.com/openbao/openbao/pull/3388
- https://github.com/openbao/openbao/pull/3472
- https://github.com/openbao/openbao/commit/0f2d90c331f25d1c6cd108638da03f4c7bd949...
- https://github.com/hashicorp/vault/blob/main/CHANGELOG.md#203
- https://github.com/advisories/GHSA-34fc-gh42-pj53
- https://github.com/openbao/openbao Product
- https://github.com/openbao/openbao/commit/763625a2072103ea9e9122f2a8408e0b988d28...
- https://github.com/openbao/openbao/releases/tag/v2.6.0
Severity
9.2
Critical
CVSS 4.0: 9.1 (GHSA)
Exploitation
EPSS <1%
Type
CWE-208Observable Timing Discrepancy
Timeline
Published23 Sep 2026
Updated27 Sep 2026
First seen22 Sep 2026
Sources
GHSA-34fc-gh42-pj53 · GHSA
CVE-2026-63132 · NVD
GHSA-34fc-gh42-pj53 · OSV
CVE-2026-63132 · MITRE
Track software like this
Free during beta