CVE-2026-39946
Last modified
CVE-2026-39946 is a medium-severity vulnerability rated 4.9/10 on the CVSS scale. OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, when OpenBao revoked privileges on a role in the PostgreSQL database secrets engine, OpenBao failed to use proper database quoting on schema names provided by PostgreSQL. EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, when OpenBao revoked privileges on a role in the PostgreSQL database secrets engine, OpenBao failed to use proper database quoting on schema names provided by PostgreSQL. This could lead to role revocation failures, or more rarely, SQL injection as the management user. This vulnerability was original from HashiCorp Vault. The vulnerability is addressed in v2.5.3. As a workaround, audit table schemas and ensure database users cannot create new schemas and grant privileges on them.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Openbao | Openbao | < 2.5.3 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-39946?
How severe is CVE-2026-39946?
How do I fix CVE-2026-39946?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-39938Cacti is an open source performance and fault management fra…9.8
- CVE-2026-3994A vulnerability was detected in rui314 mold up to 2.40.4. Th…5.3
- CVE-2026-39940ChurchCRM is an open-source church management system. Prior …5.3
- CVE-2026-39941ChurchCRM is an open-source church management system. Prior …6.1
- CVE-2026-39942Directus is a real-time API and App dashboard for managing S…8.8
- CVE-2026-39943Directus is a real-time API and App dashboard for managing S…6.5
- CVE-2026-39948Cacti is an open source performance and fault management fra…9.8
- CVE-2026-3995The OPEN-BRAIN plugin for WordPress is vulnerable to Stored …4.4
- CVE-2026-39951Cacti is an open source performance and fault management fra…8.8
- CVE-2026-39955Cacti is an open source performance and fault management fra…9.8
- CVE-2026-39956jq is a command-line JSON processor. In commits after 69785b…6.1
- CVE-2026-39957Lychee is a free, open-source photo-management tool. Prior t…4.3
Are you affected by CVE-2026-39946?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
