CVE-2026-55774: OpenBao: Cross-namespace lease revocation/renewal via canonical sys/leases/{revoke,renew} — incomplete fix of CVE-2026-45808
OpenBao users with access to the sys/leases/revoke/:lease_id endpoint in any namespace can revoke leases in any other namespace as long as the lease identifier is known to them, bypassing ACLs that should apply for cross-namespace revocations.
References
- github.com/advisories/GHSA-c36x-h252-g9x2
- github.com/openbao/openbao/commit/b20b999dd4044d7b419a5472d8fe08407828be37
- github.com/openbao/openbao/pull/3307
- github.com/openbao/openbao/releases/tag/v2.5.5
- github.com/openbao/openbao/security/advisories/GHSA-c36x-h252-g9x2
- nvd.nist.gov/vuln/detail/CVE-2026-55774
Code Behaviors & Features
Detect and mitigate CVE-2026-55774 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →