Skip to main content

Critical RCE Alert: Full takeover of HashiCorp Vault and OpenBao. OpenBao is patched. Vault remains exposed

0
Critical
Published: 09/29/2026 (09/29/2026, 21:43:15 UTC)
Source: Reddit NetSec

Description

A critical remote code execution (RCE) vulnerability chain has been demonstrated affecting OpenBao and HashiCorp Vault. OpenBao has released patches in versions 2.6.3 and 2.7.0 to fully mitigate the issue. However, HashiCorp Vault remains exposed due to a lack of coordinated disclosure and official mitigation. The exploit requires only unauthenticated access and a specific Raft snapshot policy to achieve full server compromise. This is the second RCE ever found in Vault's codebase and is considered highly plausible in real-world environments.

Reddit Discussion

r/netsec·posted by u/the_hypotenuse
00

OpenBao engineers at ControlPlane have chained 4 vulnerabilities to show how under certain conditions, an OpenBao or Vault server can be completely compromised from an unauthenticated position. This is only the second RCE ever found in the Vault codebase.

The exploit is highly plausible in real-world environments, requiring only an unauthenticated entry path and a defined Raft snapshot policy to trigger a complete server compromise.

If you are impacted, upgrade as soon as possible to OpenBao 2.6.3 or 2.7.0

While OpenBao is fully patched, HashiCorp Vault remains exposed as of writing. Unfortunately, IBM's unwillingness to coordinate a mutual disclosure policy means Vault users currently lack an official mitigation

Affected software

Affected versions
=2.6.3=2.7.0

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/29/2026, 22:06:17 UTC

Technical Analysis

ControlPlane and OpenBao engineers identified and chained four vulnerabilities to demonstrate a full remote code execution exploit chain in OpenBao and HashiCorp Vault. The exploit allows an unauthenticated attacker to fully compromise the server if a Raft snapshot policy is configured. OpenBao has patched this vulnerability in versions 2.6.3 and 2.7.0, but HashiCorp Vault remains vulnerable as of the latest reports due to IBM's lack of coordinated disclosure and mitigation. This vulnerability is notable as only the second RCE found in Vault's codebase, highlighting a significant security risk for users of these secrets management platforms.

Potential Impact

Successful exploitation leads to complete server takeover via remote code execution from an unauthenticated position. This compromises the confidentiality, integrity, and availability of the affected secrets management systems. OpenBao users who have not upgraded remain at risk, while Vault users currently have no official mitigation, increasing their exposure.

Mitigation Recommendations

OpenBao users should upgrade immediately to versions 2.6.3 or 2.7.0 where the vulnerability is fully patched. HashiCorp Vault users currently lack an official fix or mitigation due to the absence of coordinated disclosure by IBM. Users should monitor vendor advisories closely and apply any future patches promptly. Patch status for Vault is not yet confirmed; check the vendor advisory for updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
netsec
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Newsworthiness Assessment
{"score":46,"reasons":["external_link","newsworthy_keywords:rce,exposed,patch","urgent_news_indicators","established_author","very_recent"],"isNewsworthy":true,"foundNewsworthy":["rce","exposed","patch"]}
Has External Source
true
Trusted Domain
false

Threat ID: 6abc3654680226ef6859a16c

Added to database: 09/29/2026, 22:06:12 UTC

Last enriched: 09/29/2026, 22:06:17 UTC

Last updated: 09/29/2026, 23:36:11 UTC

Views: 5

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses