CVE Explorer
CVE-2025-64761
OpenBao is an open source identity-based secrets management system. Prior to version 2.4.4, a privileged operator could use the identity group subsystem to add a root policy to a group identity group, escalating their or another user's permissions in the system. Specifically this is an issue when: an operator in the root namespace has access to identity/groups endpoints and an operator does not have policy access. Otherwise, an operator with policy access could create or modify an existing polic
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"openbao","vendor":"openbao","versions":[{"status":"affected","version":"< 2.4.4"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:db2c0b9a11fd20b59c2d541391d2430945a6953e47489349acfe7cdcd6cb34f9 · sha256:c8ea193ffac69abf… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"NETWORK","baseScore":7.5,"baseSeverity":"HIGH","privilegesRequired":"HIGH","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:db2c0b9a11fd20b59c2d541391d2430945a6953e47489349acfe7cdcd6cb34f9 · sha256:c8ea193ffac69abf… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-266","description":"CWE-266: Incorrect Privilege Assignment","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:db2c0b9a11fd20b59c2d541391d2430945a6953e47489349acfe7cdcd6cb34f9 · sha256:c8ea193ffac69abf… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"name":"https://github.com/openbao/openbao/commit/16bb0ccd37a502930a289d434cbe4e7b4edd66e5","tags":["x_refsource_MISC"],"url":"https://github.com/openbao/openbao/commit/16bb0ccd37a502930a289d434cbe4e7b4edd66e5"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:db2c0b9a11fd20b59c2d541391d2430945a6953e47489349acfe7cdcd6cb34f9 · sha256:c8ea193ffac69abf… · /containers/cna/references/2
{"name":"https://github.com/openbao/openbao/pull/2143","tags":["x_refsource_MISC"],"url":"https://github.com/openbao/openbao/pull/2143"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:db2c0b9a11fd20b59c2d541391d2430945a6953e47489349acfe7cdcd6cb34f9 · sha256:c8ea193ffac69abf… · /containers/cna/references/1
{"name":"https://github.com/openbao/openbao/security/advisories/GHSA-7ff4-jw48-3436","tags":["x_refsource_CONFIRM"],"url":"https://github.com/openbao/openbao/security/advisories/GHSA-7ff4-jw48-3436"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:db2c0b9a11fd20b59c2d541391d2430945a6953e47489349acfe7cdcd6cb34f9 · sha256:c8ea193ffac69abf… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.