lowVulnerability
CVE-2026-77285
### Impact During certain error conditions, OpenBao Agent's exec rendering mode will incorrectly write secrets specified in `env_template` to stdout. This primarily happens when `num_retries` is met. This vulnerability is original to Vault and was reported via the OpenBao security mailing list. ### Patches This is addressed in OpenBao v2.6.0 GA.
Properties
- ghsa_id
- GHSA-444v-8vxr-p36h
- summary
- OpenBao Agent Writes Secrets to Stdout
- severity
- low
- cve_id
- CVE-2026-77285
- signal_observed_at
- 2026-09-23T04:35:57+00:00
- is_ghsa_only
- false
- ghsa_published
- 2026-09-22T20:36:46Z
- source_url
- https://github.com/advisories/GHSA-444v-8vxr-p36h
- ghsa_updated
- 2026-09-22T20:36:48Z
Related Entities (4)
HAS_WEAKNESS (1)
→[Weakness]Insertion of Sensitive Information into Log File
REPORTED_BY (1)
→[Source]GitHub Advisory Database
VULNERABLE_TO (1)
←[Software]go/github.com/openbao/openbao
AFFECTS (1)
→[Software]go/github.com/openbao/openbao
Explore deeper with Ninja Signal's threat intelligence graph