You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
OpenBao Skips Stricter Deny Policy for LIST operations
Moderate severity
GitHub Reviewed
Published
Jul 14, 2026
in
openbao/openbao
•
Updated Sep 22, 2026
When a policy operator has written capabilities = ["deny"] on a path with a trailing wildcard but allowed a broader list operation (e.g., a deny on secrets/metadata/restricted/* but allowed list on secrets/metadata/*), OpenBao would incorrectly allow the operation. This did not impact other operation types.
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Learn more on MITRE.
Impact
When a policy operator has written
capabilities = ["deny"]on a path with a trailing wildcard but allowed a broader list operation (e.g., adenyonsecrets/metadata/restricted/*but allowedlistonsecrets/metadata/*), OpenBao would incorrectly allow the operation. This did not impact other operation types.Patches
This has been patched in OpenBao v2.6.0.
References