CVE-2026-33757
openbao openbao, Cryostat 4
OpenBao is an open source identity-based secrets management system. Prior to version 2.5.2, OpenBao does not prompt for user confirmation when logging in via JWT/OIDC and a role with `callback_mode` set to `direct`. This allows an attacker to start an authentication request and perform "remote phishing" by having the victim visit the URL and automatically log-in to the session of the attacker. Despite being based on the authorization code flow, the `direct` mode calls back directly to the API and allows an attacker to poll for an OpenBao token until it is issued. Version 2.5.2 includes an a...
- CVSS
- 8.3
- EPSS
- 0.41% 33.8% percentile
- CISA KEV
- Not listed
- Published
- 2026.03.28