Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. github.com/openbao/openbao
  4. ›
  5. CVE-2025-64761

CVE-2025-64761: OpenBao is Vulnerable to Privileged Operator Identity Group Root Escalation

November 24, 2025 (updated November 27, 2025)

Similar to HCSEC-2025-13 / CVE-2025-5999, a privileged operator could use the identity group subsystem to add a root policy to a group identity group, escalating their or another user’s permissions in the system. Specifically this is an issue when:

  1. An operator in the root namespace has access to identity/groups endpoints.
  2. An operator does not have policy access.

Otherwise, an operator with policy access could create or modify an existing policy to grant root-equivalent permissions through the sudo capability.

References

  • github.com/advisories/GHSA-7ff4-jw48-3436
  • github.com/openbao/openbao
  • github.com/openbao/openbao/commit/16bb0ccd37a502930a289d434cbe4e7b4edd66e5
  • github.com/openbao/openbao/commit/747a1378c2756f86296ad9450f74f6faeecc2eb7
  • github.com/openbao/openbao/pull/2143
  • github.com/openbao/openbao/releases/tag/v2.4.4
  • github.com/openbao/openbao/security/advisories/GHSA-7ff4-jw48-3436
  • nvd.nist.gov/vuln/detail/CVE-2025-64761

Code Behaviors & Features

Detect and mitigate CVE-2025-64761 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 2.4.4

Fixed versions

  • 2.4.4

Solution

Upgrade to version 2.4.4 or above.

Impact 7.2 HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-266: Incorrect Privilege Assignment
  • CWE-269: Improper Privilege Management

Source file

go/github.com/openbao/openbao/CVE-2025-64761.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Mon, 08 Dec 2025 12:21:30 +0000.