GHSA-59w7-v8rr-pr4p

Suggest an improvement
Source
https://github.com/advisories/GHSA-59w7-v8rr-pr4p
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-59w7-v8rr-pr4p/GHSA-59w7-v8rr-pr4p.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-59w7-v8rr-pr4p
Aliases
Published
2026-09-22T20:36:49Z
Modified
2026-09-22T21:00:07Z
Severity
  • 7.5 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
OpenBao's Templated Policies Allow Privilege Escalation via Wildcard Characters
Details

Impact

ACL Policies

OpenBao supports "templated polices": Policies with placeholders that are replaced at evaluation time.

This allows you to write a single policy which e.g. grants user "alice" access to all entries in a key value engine prefixed with alice/ while granting "bob" access to bob/, "carol" access to carol/, etc.

If the data used in the template can be controlled by an attacker (e.g. your system allows the user to freely select their username) and "globbing" characters are considered valid ( e.g. * is a valid username) they will be able to escalate their privileges.

The problematic characters are *, + and /.

PKI Secrets Engine allowed_uri_sans_template and allowed_domains Polices

The PKI secrets engine allows you to limit the "common names" a user can requests a TLS certificate for. Similar to the ACL polices this allows you to restrict e.g. "alice" to alice.example.com, "bob" to bob.example.com, etc. via templates.

Again, if an attacker can control this data freely, they can trick the PKI engine into using e.g. the *.example.com glob effectively allowing them to issue certificates for any subdomain of example.com

The problematic character in this case is *.

SSH Secrets Engine allowed_users and allowed_domains Polices

The SSH secrets engine allows you to limit the "principal" a user can request as SSH certificate for. Similar to ACL and PKI, this allows templates.

The problematic character in this case is , as the template result is split at all commas and each entry will be allowed.

Am I affected?

You are affected, if a) you use a templated policy (ACL, PKI or SSH) and b) your users can modify data used by your template freely.

If you can guarantee that the data used in your templates will never contain the problematic characters, you are not affected. For example, if you use {{ identity.entity.id }} in your policy, you are not affected, because identity.entity.id is randomly generated by OpenBao.

Even with this vulnerability patched: Using user controllable data in your policies is probably not the best idea.

Patches

All three have been patched in OpenBao v2.6.0.

Database specific
{
    "cwe_ids":  [
        "CWE-863"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-09-22T20:36:49Z",
    "nvd_published_at":  "2026-09-21T15:17:31Z",
    "severity":  "HIGH"
}
References

Affected packages

Go / github.com/openbao/openbao

Package

Name
github.com/openbao/openbao
View open source insights on deps.dev
Purl
pkg:golang/github.com/openbao/openbao

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.0.0-20260710001938-2d4ebafec5c5

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-59w7-v8rr-pr4p/GHSA-59w7-v8rr-pr4p.json"

Go / github.com/openbao/openbao

Package

Name
github.com/openbao/openbao
View open source insights on deps.dev
Purl
pkg:golang/github.com/openbao/openbao

Affected ranges

Type
SEMVER
Events
Introduced
0.1.0
Last Affected
1.1.5

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-59w7-v8rr-pr4p/GHSA-59w7-v8rr-pr4p.json"