OpenBao: Privileged Operator May Execute Code on the Underlying Host (CVE-2025-54997)
OpenBao versions 2.3.1 and below contain a critical vulnerability that allows privileged API operators to bypass intended restrictions on system code execution and network connections via the audit subsystem. By manipulating log prefixes, these operators can execute unauthorized code and access the network, violating the security model. This issue is fixed in version 2.3.2. As a workaround, users can block access to sys/audit/* endpoints with explicit deny policies, but root operators cannot be restricted this way.
AI Analysis
Technical Summary
OpenBao is a software solution for managing sensitive data such as secrets, certificates, and keys. In versions 2.3.1 and earlier, privileged API operators are supposed to be restricted from executing system code or making network connections. However, these restrictions can be bypassed through the audit subsystem by manipulating log prefixes, enabling unauthorized code execution and network access. This vulnerability violates the intended security model and is addressed in OpenBao version 2.3.2. A temporary mitigation involves blocking access to sys/audit/* endpoints via explicit deny policies, though this does not apply to root operators.
Potential Impact
Privileged API operators in affected OpenBao versions can bypass restrictions and execute arbitrary code on the underlying host as well as initiate network connections. This undermines the security model designed to limit operator capabilities, potentially leading to unauthorized system compromise and data exposure. Root operators remain unrestricted by the workaround, maintaining a high risk if compromised.
Mitigation Recommendations
A fix is available in OpenBao version 2.3.2; users should upgrade to this version to remediate the vulnerability. As a temporary workaround, users can block access to sys/audit/* endpoints using explicit deny policies, but this does not restrict root operators. Therefore, upgrading to the fixed version is strongly recommended.
OpenBao: Privileged Operator May Execute Code on the Underlying Host (CVE-2025-54997)
Description
OpenBao versions 2.3.1 and below contain a critical vulnerability that allows privileged API operators to bypass intended restrictions on system code execution and network connections via the audit subsystem. By manipulating log prefixes, these operators can execute unauthorized code and access the network, violating the security model. This issue is fixed in version 2.3.2. As a workaround, users can block access to sys/audit/* endpoints with explicit deny policies, but root operators cannot be restricted this way.
Affected software
pkg:bitnami/openbaoRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
OpenBao is a software solution for managing sensitive data such as secrets, certificates, and keys. In versions 2.3.1 and earlier, privileged API operators are supposed to be restricted from executing system code or making network connections. However, these restrictions can be bypassed through the audit subsystem by manipulating log prefixes, enabling unauthorized code execution and network access. This vulnerability violates the intended security model and is addressed in OpenBao version 2.3.2. A temporary mitigation involves blocking access to sys/audit/* endpoints via explicit deny policies, though this does not apply to root operators.
Potential Impact
Privileged API operators in affected OpenBao versions can bypass restrictions and execute arbitrary code on the underlying host as well as initiate network connections. This undermines the security model designed to limit operator capabilities, potentially leading to unauthorized system compromise and data exposure. Root operators remain unrestricted by the workaround, maintaining a high risk if compromised.
Mitigation Recommendations
A fix is available in OpenBao version 2.3.2; users should upgrade to this version to remediate the vulnerability. As a temporary workaround, users can block access to sys/audit/* endpoints using explicit deny policies, but this does not restrict root operators. Therefore, upgrading to the fixed version is strongly recommended.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- BIT-openbao-2025-54997
- Osv Schema Version
- 1.6.2
- Aliases
- ["CVE-2025-54997"]
- Ecosystems
- ["Bitnami"]
- Database Specific Severity
- Critical
- Cvss Version
- null
Threat ID: 6aa005f6acd9273b49ab63c5
Added to database: 09/08/2026, 12:56:22 UTC
Last enriched: 09/08/2026, 13:33:21 UTC
Last updated: 09/08/2026, 22:52:07 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.