<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T21:28:12.844708+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-11283</id>
    <title>bdu:2025-11283</title>
    <updated>2026-10-03T21:28:12.850997+00:00</updated>
    <content>bdu:2025-11283</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-11283"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-openbao-2025-54996</id>
    <title>BIT-openbao-2025-54996 — OpenBao Root Namespace Operator May Elevate Token Privileges</title>
    <updated>2026-10-03T21:28:12.851035+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: openbao</p>
<p>OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 2.3.1 and below, accounts with access to highly-privileged identity entity systems in root namespaces were able to increase their scope directly to the root policy. While the identity system allowed adding arbitrary policies, which in turn could contain capability grants on arbitrary paths, the root policy was restricted to manual generation using unseal or recovery key shares. The global root policy was not accessible from child namespaces. This issue is fixed in version 2.3.2. To workaround this vulnerability, use of denied_parameters in any policy which has access to the affected identity endpoints (on identity entities) may be sufficient to prohibit this type of attack.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-openbao-2025-54996"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2025-18597</id>
    <title>cnvd-2025-18597</title>
    <updated>2026-10-03T21:28:12.851090+00:00</updated>
    <content>cnvd-2025-18597</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2025-18597"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-249392</id>
    <title>EUVD-2026-249392</title>
    <updated>2026-10-03T21:28:12.851112+00:00</updated>
    <content>EUVD-2026-249392</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-249392"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-54996</id>
    <title>fkie_cve-2025-54996</title>
    <updated>2026-10-03T21:28:12.851131+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 2.3.1 and below, accounts with access to highly-privileged identity entity systems in root namespaces were able to increase their scope directly to the root policy. While the identity system allowed adding arbitrary policies, which in turn could contain capability grants on arbitrary paths, the root policy was restricted to manual generation using unseal or recovery key shares. The global root policy was not accessible from child namespaces. This issue is fixed in version 2.3.2. To workaround this vulnerability, use of denied_parameters in any policy which has access to the affected identity endpoints (on identity entities) may be sufficient to prohibit this type of attack.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-54996"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-vf84-mxrq-crqc</id>
    <title>GHSA-vf84-mxrq-crqc — OpenBao Root Namespace Operator May Elevate Token Privileges</title>
    <updated>2026-10-03T21:28:12.851176+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/openbao/openbao</p>
<p>### Impact</p>
<p>Accounts with access to the highly-privileged identity entity system in the root namespace may increase their scope directly to the `root` policy. While the identity system always allowed adding arbitrary policies, which in turn could contain capability grants on arbitrary paths, the `root` policy is restricted to manual generation using unseal or recovery key shares. The global `root` policy is not accessible from child namespaces.</p>
<p>### Patches</p>
<p>OpenBao v2.3.2 will patch this issue.</p>
<p>### Workarounds</p>
<p>Use of `denied_parameters` in any policy which has access to the affected identity endpoints (on [identity entities](https://openbao.org/api-docs/secret/identity/entity/)) may be sufficient to prohibit this type of attack.</p>
<p>### References</p>
<p>This issue was disclosed to HashiCorp and is the OpenBao equivalent of the following tickets:</p>
<p>- https://discuss.hashicorp.com/t/hcsec-2025-13-vault-root-namespace-operator-may-elevate-token-privileges/76032
- https://nvd.nist.gov/vuln/detail/cve-2025-5999</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-vf84-mxrq-crqc"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15434-1</id>
    <title>openSUSE-SU-2025:15434-1 — govulncheck-vulndb-0.0.20250811T192933-1.1 on GA media</title>
    <updated>2026-10-03T21:28:12.851251+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>govulncheck-vulndb-0.0.20250811T192933-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15434-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1855</id>
    <title>WID-SEC-W-2025-1855 — OpenBao: Mehrere Schwachstellen</title>
    <updated>2026-10-03T21:28:12.851280+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter oder anonymer Angreifer kann mehrere Schwachstellen in OpenBao ausnutzen, um beliebigen Code auszuführen, Root-Rechte zu erlangen, Sicherheitsmaßnahmen zu umgehen und vertrauliche Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1855"/>
  </entry>
</feed>
