Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-444v-8vxr-p36h | OpenBao Agent Writes Secrets to Stdout |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 23 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 23 Sep 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openbao
Openbao openbao |
|
| Vendors & Products |
Openbao
Openbao openbao |
Wed, 23 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, OpenBao Agent's exec rendering mode could write secrets from env_template to standard output when command/agent/exec/exec.go re-created the template runner after repeated rendering failures, primarily after num_retries was reached. A process supervisor, log collector, or local user able to read that output could obtain the rendered secret values. This issue is fixed in version 2.6.0. | |
| Title | OpenBao Agent Writes Secrets to Stdout | |
| Weaknesses | CWE-532 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-23T19:23:54.659Z
Reserved: 2026-08-20T19:14:21.331Z
Link: CVE-2026-77285
Updated: 2026-09-23T19:23:52.060Z
Status : Received
Published: 2026-09-23T19:19:15.180
Modified: 2026-09-23T20:17:15.547
Link: CVE-2026-77285
No data.
OpenCVE Enrichment
Updated: 2026-09-23T20:00:08Z
Github GHSA