Skip to content
Critical RCE Vulnerability in OpenBao and Vault Exposed

Critical RCE Vulnerability in OpenBao and Vault Exposed

First seen 30 Sep 2026, 00:05 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 30, 2026 at 00:06 UTC
  • •OpenBao and Vault have critical RCE vulnerabilities requiring immediate patching.
  • •Only OpenBao is fully patched; HashiCorp Vault remains vulnerable.
  • •The exploit chain involves unauthenticated access and specific server configurations.

OpenBao engineers at ControlPlane disclosed a critical remote code execution (RCE) vulnerability affecting both OpenBao and HashiCorp Vault, allowing unauthenticated attackers to fully compromise servers under specific conditions. This exploit chain leverages four vulnerabilities, marking the second RCE ever found in the Vault codebase. Users are urged to upgrade to OpenBao versions 2.6.3 or 2.7.0, as OpenBao has been fully patched. However, HashiCorp Vault remains exposed due to a lack of coordinated disclosure from IBM. The exploit requires an unauthenticated entry point and a defined Raft snapshot policy to trigger a complete server compromise. As of the latest reports, Vault users lack an official mitigation. The vulnerabilities were reported by independent researchers and patched in the latest OpenBao release.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-29
OpenBao vulnerabilities disclosed
ControlPlane revealed a critical RCE exploit chain affecting OpenBao and Vault, urging users to upgrade to patched versions.
Control-Plane
2026-09-29
Reddit alert on Vault exposure
A Reddit post highlighted that while OpenBao is patched, HashiCorp Vault remains exposed due to uncoordinated disclosure.
Reddit

More articles in this cluster (2)

Following this threat?

Track ControlPlane in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed