Critical RCE Alert: Full takeover of HashiCorp Vault and OpenBao. OpenBao is patched. Vault remains exposed
A critical remote code execution (RCE) vulnerability chain has been demonstrated affecting OpenBao and HashiCorp Vault. OpenBao has released patches in versions 2.6.3 and 2.7.0 to fully mitigate the issue. However, HashiCorp Vault remains exposed due to a lack of coordinated disclosure and official mitigation. The exploit requires only unauthenticated access and a specific Raft snapshot policy to achieve full server compromise. This is the second RCE ever found in Vault's codebase and is considered highly plausible in real-world environments.
AI Analysis
Technical Summary
ControlPlane and OpenBao engineers identified and chained four vulnerabilities to demonstrate a full remote code execution exploit chain in OpenBao and HashiCorp Vault. The exploit allows an unauthenticated attacker to fully compromise the server if a Raft snapshot policy is configured. OpenBao has patched this vulnerability in versions 2.6.3 and 2.7.0, but HashiCorp Vault remains vulnerable as of the latest reports due to IBM's lack of coordinated disclosure and mitigation. This vulnerability is notable as only the second RCE found in Vault's codebase, highlighting a significant security risk for users of these secrets management platforms.
Potential Impact
Successful exploitation leads to complete server takeover via remote code execution from an unauthenticated position. This compromises the confidentiality, integrity, and availability of the affected secrets management systems. OpenBao users who have not upgraded remain at risk, while Vault users currently have no official mitigation, increasing their exposure.
Mitigation Recommendations
OpenBao users should upgrade immediately to versions 2.6.3 or 2.7.0 where the vulnerability is fully patched. HashiCorp Vault users currently lack an official fix or mitigation due to the absence of coordinated disclosure by IBM. Users should monitor vendor advisories closely and apply any future patches promptly. Patch status for Vault is not yet confirmed; check the vendor advisory for updates.
Critical RCE Alert: Full takeover of HashiCorp Vault and OpenBao. OpenBao is patched. Vault remains exposed
Description
A critical remote code execution (RCE) vulnerability chain has been demonstrated affecting OpenBao and HashiCorp Vault. OpenBao has released patches in versions 2.6.3 and 2.7.0 to fully mitigate the issue. However, HashiCorp Vault remains exposed due to a lack of coordinated disclosure and official mitigation. The exploit requires only unauthenticated access and a specific Raft snapshot policy to achieve full server compromise. This is the second RCE ever found in Vault's codebase and is considered highly plausible in real-world environments.
Reddit Discussion
OpenBao engineers at ControlPlane have chained 4 vulnerabilities to show how under certain conditions, an OpenBao or Vault server can be completely compromised from an unauthenticated position. This is only the second RCE ever found in the Vault codebase.
The exploit is highly plausible in real-world environments, requiring only an unauthenticated entry path and a defined Raft snapshot policy to trigger a complete server compromise.
If you are impacted, upgrade as soon as possible to OpenBao 2.6.3 or 2.7.0
While OpenBao is fully patched, HashiCorp Vault remains exposed as of writing. Unfortunately, IBM's unwillingness to coordinate a mutual disclosure policy means Vault users currently lack an official mitigation
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
ControlPlane and OpenBao engineers identified and chained four vulnerabilities to demonstrate a full remote code execution exploit chain in OpenBao and HashiCorp Vault. The exploit allows an unauthenticated attacker to fully compromise the server if a Raft snapshot policy is configured. OpenBao has patched this vulnerability in versions 2.6.3 and 2.7.0, but HashiCorp Vault remains vulnerable as of the latest reports due to IBM's lack of coordinated disclosure and mitigation. This vulnerability is notable as only the second RCE found in Vault's codebase, highlighting a significant security risk for users of these secrets management platforms.
Potential Impact
Successful exploitation leads to complete server takeover via remote code execution from an unauthenticated position. This compromises the confidentiality, integrity, and availability of the affected secrets management systems. OpenBao users who have not upgraded remain at risk, while Vault users currently have no official mitigation, increasing their exposure.
Mitigation Recommendations
OpenBao users should upgrade immediately to versions 2.6.3 or 2.7.0 where the vulnerability is fully patched. HashiCorp Vault users currently lack an official fix or mitigation due to the absence of coordinated disclosure by IBM. Users should monitor vendor advisories closely and apply any future patches promptly. Patch status for Vault is not yet confirmed; check the vendor advisory for updates.
Technical Details
- Source Type
- Subreddit
- netsec
- Reddit Score
- 0
- Discussion Level
- minimal
- Content Source
- reddit_link_post
- Post Type
- link
- Newsworthiness Assessment
- {"score":46,"reasons":["external_link","newsworthy_keywords:rce,exposed,patch","urgent_news_indicators","established_author","very_recent"],"isNewsworthy":true,"foundNewsworthy":["rce","exposed","patch"]}
- Has External Source
- true
- Trusted Domain
- false
Threat ID: 6abc3654680226ef6859a16c
Added to database: 09/29/2026, 22:06:12 UTC
Last enriched: 09/29/2026, 22:06:17 UTC
Last updated: 09/29/2026, 23:36:11 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.