CVE-2026-63132

CVE-2026-63132 published: OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, OpenBao's handleLogicalRecovery path in http/logical.go compared the highly privileged recovery token with ordinary string equality. A remote unauthenticated attacker able t...

View full NVD advisory → ← Back to CVE watch