Control-Plane Critical RCE Vulnerability in OpenBao and Vault Exposed
Article Content
- •OpenBao and Vault have critical RCE vulnerabilities requiring immediate patching.
- •Only OpenBao is fully patched; HashiCorp Vault remains vulnerable.
- •The exploit chain involves unauthenticated access and specific server configurations.
OpenBao engineers at ControlPlane disclosed a critical remote code execution (RCE) vulnerability affecting both OpenBao and HashiCorp Vault, allowing unauthenticated attackers to fully compromise servers under specific conditions. This exploit chain leverages four vulnerabilities, marking the second RCE ever found in the Vault codebase. Users are urged to upgrade to OpenBao versions 2.6.3 or 2.7.0, as OpenBao has been fully patched. However, HashiCorp Vault remains exposed due to a lack of coordinated disclosure from IBM. The exploit requires an unauthenticated entry point and a defined Raft snapshot policy to trigger a complete server compromise. As of the latest reports, Vault users lack an official mitigation. The vulnerabilities were reported by independent researchers and patched in the latest OpenBao release.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track ControlPlane in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…