Severity of the code-execution flaw (GHSA-j6wc-jpvg-xfxq): CVSSv4 9.4 (Critical) (Source: ControlPlane (September 29, 2026))
The system that stores your passwords, keys and certificates has to hold up under pressure. ControlPlane, a security firm, has shown how four separate flaws in OpenBao can work together. The chain runs from network access to an attacker running their own code on the server.
The lesson is in the order of the steps. The last flaw is critical on its own. It lets an attacker run code after restoring a snapshot, a saved copy of the server's data. But the attacker first needs access to the snapshot restore endpoint. In this chain, three High-severity flaws supplied that access. They carried the attacker from a narrow sandbox role to an admin role, then out of the sandbox namespace. A patch queue ranked one bug at a time can miss that.
What ControlPlane reported
ControlPlane worked with the OpenBao community on the fix. It calls this the second remote code execution flaw ever found in Vault and OpenBao. The chain combines disclosures from three independent reporters. The fixes shipped in OpenBao v2.6.3 and v2.7.0.
HashiCorp Vault is in a different position. ControlPlane built the chain from exploits it knows affect Vault Community Edition. It suspects Vault Enterprise is affected too, but has not confirmed it. The firm says it will update its post when IBM's HashiCorp Vault remediates.
How the chain works
ControlPlane's scenario starts with an attacker already inside the network. An application runs in a sandboxed area of OpenBao called a namespace. Applications prove who they are with SPIFFE, an identity standard for software workloads. One certificate authority in OpenBao issues those identities. The same authority also has ACME switched on. ACME is the automated certificate protocol that Let's Encrypt made common.
Step one uses GHSA-x8fg-h69x-p28f (CVSSv4 8.2, High), a flaw in ACME validation. The attacker must know the identity of a service provisioner, a tightly scoped account. The attacker must also be able to solve ACME challenges for any domain. With both, the attacker gets a certificate for that identity and can log in as that account.
This step has a condition. By default, OpenBao's ACME does not issue certificates with the ClientAuth field. ControlPlane calls that field a non-standard addition, made for certain Kubernetes and container workloads. So the chain as shown relies on a setup that is not the default.
Step two uses GHSA-fg5x-7whg-6c28 (CVSSv4 7.6, High). Access rules can be dodged by writing a path in an unexpected form, such as "AdMiN". The attacker rewrites the admin role so the provisioner's identity qualifies. The scenario assumes the admin's own identity is harder to guess.
Step three uses GHSA-mjch-vcw3-hhmf (CVSSv4 7.7, High). As sandbox admin, the attacker edits a policy so it reaches into the root namespace. Logging in again gives the attacker a token for the snapshot restore endpoint.
Step four uses GHSA-j6wc-jpvg-xfxq. The attacker restores a snapshot of their own making and unseals the node with their own keys. Code then runs. The attacker must guess the SHA-256 checksum of a program already on the system. One attempt can carry many guesses.
Treat the demonstration as narrow. The first two links fit this particular setup. Other flaws fixed in the same release help attackers in other environments. ControlPlane has held back its full working exploit. It says it will publish once users have had time to update.
Old conveniences, new exposure
ControlPlane says many root causes sat unnoticed for years. Case normalisation, added to be user-friendly, is widespread in the project. The policy bypass comes from a path-cleaning function that allows path traversal. The core of plugin execution has changed little in several years.
This shows a familiar pattern. Features added for convenience become the seams that attackers later pull apart. Reviewing each feature alone will not find them. Someone has to ask how the pieces behave together.
ControlPlane says the one exception was later found again with AI. It also reports more false positives, and cases where AI vastly underestimated a real problem. Every report still needs a person to sort it.
Two codebases, two clocks
Many flaws in Vault affect OpenBao, and the reverse. ControlPlane says the two projects have no mutual disclosure agreement. It says OpenBao's maintainers stopped proactively coordinating with HashiCorp after several one-sided disclosures, including last year's code execution flaw. It also says IBM has been unwilling to sign an agreement. In its words, Vault customers were affected at release "with no mitigations in place."
That is ControlPlane's account. The firm also sells enterprise support for OpenBao, so weigh it accordingly. The risk it describes is still plain. Two products can share flaws while their fixes ship on different schedules.
What to ask your team
First, do we run OpenBao or Vault? If OpenBao, are we on v2.6.3, v2.7.0 or later? ControlPlane says the project expects another patch set in the coming weeks.
Second, if we run Vault, who is watching for IBM's fix? What controls cover us until then?
Third, is ACME enabled on any certificate authority that also issues workload identities? ControlPlane says operators can require External Account Bindings. That forces ACME clients to authenticate first.
Fourth, do our access policies refer to canonical path forms? Who can change token policies in authentication methods? ControlPlane says most of these attacks leave obvious traces in audit logs. Is anyone alerting on them? The firm adds that beyond tight policy scoping, many of these flaws are hard to mitigate without an upgrade.
A secrets vault is only as strong as the seams between its rules. Ask who checks how those rules behave together.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: control-plane.io.





