OpenBao lacks user confirmation for OIDC direct callback mode (CVE-2026-33757)
OpenBao versions prior to 2.5.2 lack a user confirmation prompt when logging in via JWT/OIDC with roles configured for direct callback mode. This flaw allows an attacker to initiate an authentication request that automatically logs a victim into the attacker's session by tricking them into visiting a crafted URL. The vulnerability is addressed in version 2.5.2 by adding a manual confirmation screen for direct callback logins.
AI Analysis
Technical Summary
OpenBao, an open source identity-based secrets management system, has a vulnerability (CVE-2026-33757) in versions before 2.5.2 where the JWT/OIDC login flow with roles set to callback_mode=direct does not require user confirmation. This enables an attacker to perform a remote phishing attack by convincing a user to visit a crafted URL, causing the user to be automatically logged into the attacker's session. The direct callback mode bypasses the usual authorization code flow confirmation by calling back directly to the API and allowing token polling until issuance. Version 2.5.2 fixes this by introducing a confirmation screen requiring manual user interaction to complete authentication.
Potential Impact
Successful exploitation allows an attacker to hijack a user's session by automatically logging them into the attacker's session without explicit user consent. Since OpenBao manages secrets and authentication tokens, this can lead to privilege escalation and unauthorized access to sensitive infrastructure components. The attack requires user interaction limited to visiting a crafted URL, which reduces exposure but still poses a significant risk.
Mitigation Recommendations
A fix is available in OpenBao version 2.5.2 which adds a user confirmation prompt for direct callback mode logins. Until upgrading, mitigate by removing or disabling any roles configured with callback_mode=direct or enforcing manual confirmation for every session on the token issuer side for the Client ID used by OpenBao. Follow the vendor advisory and apply the official patch from https://github.com/openbao/openbao/commit/e32103951925723e9787e33886ab6b6ec20f4964.
OpenBao lacks user confirmation for OIDC direct callback mode (CVE-2026-33757)
Description
OpenBao versions prior to 2.5.2 lack a user confirmation prompt when logging in via JWT/OIDC with roles configured for direct callback mode. This flaw allows an attacker to initiate an authentication request that automatically logs a victim into the attacker's session by tricking them into visiting a crafted URL. The vulnerability is addressed in version 2.5.2 by adding a manual confirmation screen for direct callback logins.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
OpenBao, an open source identity-based secrets management system, has a vulnerability (CVE-2026-33757) in versions before 2.5.2 where the JWT/OIDC login flow with roles set to callback_mode=direct does not require user confirmation. This enables an attacker to perform a remote phishing attack by convincing a user to visit a crafted URL, causing the user to be automatically logged into the attacker's session. The direct callback mode bypasses the usual authorization code flow confirmation by calling back directly to the API and allowing token polling until issuance. Version 2.5.2 fixes this by introducing a confirmation screen requiring manual user interaction to complete authentication.
Potential Impact
Successful exploitation allows an attacker to hijack a user's session by automatically logging them into the attacker's session without explicit user consent. Since OpenBao manages secrets and authentication tokens, this can lead to privilege escalation and unauthorized access to sensitive infrastructure components. The attack requires user interaction limited to visiting a crafted URL, which reduces exposure but still poses a significant risk.
Mitigation Recommendations
A fix is available in OpenBao version 2.5.2 which adds a user confirmation prompt for direct callback mode logins. Until upgrading, mitigate by removing or disabling any roles configured with callback_mode=direct or enforcing manual confirmation for every session on the token issuer side for the Client ID used by OpenBao. Follow the vendor advisory and apply the official patch from https://github.com/openbao/openbao/commit/e32103951925723e9787e33886ab6b6ec20f4964.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- BIT-openbao-2026-33757
- Osv Schema Version
- 1.6.2
- Aliases
- ["CVE-2026-33757"]
- Ecosystems
- ["Bitnami"]
- Database Specific Severity
- High
- Cvss Version
- null
Patch Information
Threat ID: 6aa005f4acd9273b49ab6397
Added to database: 09/08/2026, 12:56:20 UTC
Last enriched: 09/08/2026, 13:31:59 UTC
Last updated: 09/08/2026, 13:31:59 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.