CVE-2026-71543: OpenBao's Templated Policies Allow Privilege Escalation via Wildcard Characters

Published Sep 21, 2026
·
Updated

OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, templated ACL, PKI, and SSH policies could substitute attacker-controlled identity data without rejecting syntax-significant characters. In ACL templated policies, asterisks, plus signs, and slashes could alter path matching. In PKI allowedurisanstemplate and alloweddomains policies, an asterisk could broaden certificate issuance to unauthorized domains. In SSH allowedusers and alloweddomains policies, a comma could add unauthorized principals. Exploitation requires a deployment to use templated policy data that users can freely modify; templates based on the randomly generated identity.entity.id value are not affected. This could allow privilege escalation, unauthorized access, and unauthorized certificate issuance. This issue is fixed in version 2.6.0.

Affected Software

1 affected component
OpenBao OpenBao<2.6.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade OpenBao to a version that resolves this vulnerability.

    Fixed in 2.6.0

Event History

Sep 21, 2026
CVE Published
via MITRE·03:03 PM
Data Sourced
via MITRE·03:03 PM
DescriptionWeakness

Frequently Asked Questions

1

Which deployments are actually exposed to this issue?

Exposure requires templated ACL, PKI, or SSH policy fields that substitute identity data users can freely modify. Templates using the randomly generated identity.entity.id value are not affected.

2

What attacker-controlled characters are relevant for each policy type?

For ACL templated policies, asterisks, plus signs, and slashes can change path matching. For PKI allowed_uri_sans_template and allowed_domains policies, an asterisk can broaden certificate issuance; for SSH allowed_users and allowed_domains policies, a comma can add unauthorized principals.

3

What is the remediation?

Upgrade OpenBao to version 2.6.0, which fixes the issue. Until upgrading, review templated policy data and avoid using user-modifiable identity values in the affected ACL, PKI, and SSH policy fields.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203