OpenBao is an open source identity-based secrets management system. Prior to version 2.4.4, a privileged operator could use the identity group subsystem to add a root policy to a group identity group, escalating their or another user's permissions in the system. Specifically this is an issue when: an operator in the root namespace has access to identity/groups endpoints and an operator does not have policy access. Otherwise, an operator with policy access could create or modify an existing policy to grant root-equivalent permissions through the sudo capability. This issue has been patched in version 2.4.4.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-7ff4-jw48-3436 OpenBao is Vulnerable to Privileged Operator Identity Group Root Escalation
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 02 Dec 2025 00:45:00 +0900

Type Values Removed Values Added
CPEs cpe:2.3:a:openbao:openbao:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Thu, 27 Nov 2025 19:00:00 +0900

Type Values Removed Values Added
First Time appeared Openbao
Openbao openbao
Vendors & Products Openbao
Openbao openbao

Wed, 26 Nov 2025 00:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 25 Nov 2025 09:45:00 +0900

Type Values Removed Values Added
Description OpenBao is an open source identity-based secrets management system. Prior to version 2.4.4, a privileged operator could use the identity group subsystem to add a root policy to a group identity group, escalating their or another user's permissions in the system. Specifically this is an issue when: an operator in the root namespace has access to identity/groups endpoints and an operator does not have policy access. Otherwise, an operator with policy access could create or modify an existing policy to grant root-equivalent permissions through the sudo capability. This issue has been patched in version 2.4.4.
Title OpenBao Privileged Operator Identity Group Root Escalation
Weaknesses CWE-266
References
Metrics cvssV4_0

{'score': 7.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-11-26T04:55:23.789Z

Reserved: 2025-11-10T22:29:34.876Z

Link: CVE-2025-64761

cve-icon Vulnrichment

Updated: 2025-11-25T14:31:12.847Z

cve-icon NVD

Status : Analyzed

Published: 2025-11-25T01:15:46.460

Modified: 2025-12-01T15:44:38.687

Link: CVE-2025-64761

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-11-27T18:45:36Z

Weaknesses