OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-71543

HIGH · CVSS 7.5 EPSS 0.42% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-21 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

OpenBao versions prior to 2.6.0 are vulnerable due to improper handling of attacker-controlled identity data in templated ACL, PKI, and SSH policies, allowing malicious alterations that can lead to privilege escalation and unauthorized access. Exploitation is possible in deployments that permit user-modifiable templated policy data, making it critical for organizations using OpenBao for identity management to prioritize upgrading to version 2.6.0. Users managing sensitive access controls or certificate issuance should be particularly vigilant in addressing this vulnerability.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-71543
Severity
HIGH
CVSS
7.5
EPSS
0.42%

Original NVD Description

OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, templated ACL, PKI, and SSH policies could substitute attacker-controlled identity data without rejecting syntax-significant characters. In ACL templated policies, asterisks, plus signs, and slashes could alter path matching. In PKI allowed_uri_sans_template and allowed_domains policies, an asterisk could broaden certificate issuance to unauthorized domains. In SSH allowed_users and allowed_domains policies, a comma could add unauthorized principals. Exploitation requires a deployment to use templated policy data that users can freely modify; templates based on the randomly generated identity.entity.id value are not affected. This could allow privilege escalation, unauthorized access, and unauthorized certificate issuance. This issue is fixed in version 2.6.0.