OpenBao is Vulnerable to Privileged Operator Identity Group Root Escalation
Description
Published to the GitHub Advisory Database
Nov 24, 2025
Reviewed
Nov 24, 2025
Published by the National Vulnerability Database
Nov 25, 2025
Last updated
Nov 27, 2025
Impact
Similar to HCSEC-2025-13 / CVE-2025-5999, a privileged operator could use the identity group subsystem to add a root policy to a group identity group, escalating their or another user's permissions in the system. Specifically this is an issue when:
identity/groupsendpoints.Otherwise, an operator with policy access could create or modify an existing policy to grant root-equivalent permissions through the
sudocapability.Patches
Patched in version 2.4.4.
Workarounds
Users should audit the use of identity subsystem and deny operators access if it is not in use.
References