Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-08727

Опубликовано: 25 мар. 2026
Источник: fstec
CVSS3: 9.6
CVSS2: 9.7
EPSS Низкий

Описание

Уязвимость метода аутентификации JWT/OIDC системы управления секретами и шифрованием OpenBao связана с некорректным управлением сеансом. Эксплуатация уязвимости может позволить нарушителю, действующему удаленно, перехватить сеанс пользователя

Вендор

ООО «Ред Софт»
Сообщество свободного программного обеспечения

Наименование ПО

РЕД ОС
OpenBao

Версия ПО

7.3 (РЕД ОС)
8.0 (РЕД ОС)
до 2.5.2 (OpenBao)

Тип ПО

Операционная система
Прикладное ПО информационных систем

Операционные системы и аппаратные платформы

ООО «Ред Софт» РЕД ОС 7.3
ООО «Ред Софт» РЕД ОС 8.0

Уровень опасности уязвимости

Высокий уровень опасности (базовая оценка CVSS 2.0 составляет 9,7)
Критический уровень опасности (базовая оценка CVSS 3.1 составляет 9,6)

Возможные меры по устранению уязвимости

Использование рекомендаций:
Для OpenBao:
https://github.com/openbao/openbao/releases/tag/v2.5.2
https://github.com/openbao/openbao/commit/e32103951925723e9787e33886ab6b6ec20f4964
Для Ред ОС:
https://redos.red-soft.ru/search/?iblock_id=24&q=CVE-2026-33757

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Данные уточняются

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 33%
0.00411
Низкий

9.6 Critical

CVSS3

9.7 Critical

CVSS2

Связанные уязвимости

CVSS3: 8.3
redos
2 месяца назад

Уязвимость openbao

CVSS3: 9.6
redhat
4 месяца назад

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.2, OpenBao does not prompt for user confirmation when logging in via JWT/OIDC and a role with `callback_mode` set to `direct`. This allows an attacker to start an authentication request and perform "remote phishing" by having the victim visit the URL and automatically log-in to the session of the attacker. Despite being based on the authorization code flow, the `direct` mode calls back directly to the API and allows an attacker to poll for an OpenBao token until it is issued. Version 2.5.2 includes an additional confirmation screen for `direct` type logins that requires manual user interaction in order to finish the authentication. This issue can be worked around either by removing any roles with `callback_mode=direct` or enforcing confirmation for every session on the token issuer side for the Client ID used by OpenBao.

CVSS3: 9.6
nvd
4 месяца назад

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.2, OpenBao does not prompt for user confirmation when logging in via JWT/OIDC and a role with `callback_mode` set to `direct`. This allows an attacker to start an authentication request and perform "remote phishing" by having the victim visit the URL and automatically log-in to the session of the attacker. Despite being based on the authorization code flow, the `direct` mode calls back directly to the API and allows an attacker to poll for an OpenBao token until it is issued. Version 2.5.2 includes an additional confirmation screen for `direct` type logins that requires manual user interaction in order to finish the authentication. This issue can be worked around either by removing any roles with `callback_mode=direct` or enforcing confirmation for every session on the token issuer side for the Client ID used by OpenBao.

CVSS3: 9.6
debian
4 месяца назад

OpenBao is an open source identity-based secrets management system. Pr ...

CVSS3: 9.6
github
4 месяца назад

OpenBao lacks user confirmation for OIDC direct callback mode

EPSS

Процентиль: 33%
0.00411
Низкий

9.6 Critical

CVSS3

9.7 Critical

CVSS2