CVE-2026-46358

Description

A flaw was found in OpenBao. The inline authentication functionality incorrectly redacted audit log entries, causing non-authentication headers to be removed while authentication-related headers were retained in cleartext. This vulnerability requires an attacker to first compromise access to the audit device. Successful exploitation could lead to the disclosure of sensitive authentication material.

Statement

OpenBao is packaged for Fedora and EPEL. Both shipped builds (2.6.1) are newer than the fixed version (2.5.4) for this audit-log redaction flaw and are not affected.

Mitigation

No mitigation is necessary; the shipped OpenBao packages already contain the fix.

Understanding the Weakness (CWE)

Confidentiality

Technical Impact: Read Application Data

An attacker with access to the system could read sensitive information stored in cleartext (i.e., unencrypted). Even if the information is encoded in a way that is not human-readable, certain techniques could determine which encoding is being used, then decode the information.

Frequently Asked Questions

Want to get errata notifications? Sign up here.