{"id":"GHSA-59w7-v8rr-pr4p","summary":" OpenBao's Templated Policies Allow Privilege Escalation via Wildcard Characters","details":"## Impact\n\n### ACL Policies\n\nOpenBao supports \"templated polices\": Policies with placeholders that are replaced at evaluation time.\n\nThis allows you to write a single policy which e.g. grants user \"alice\" access to all entries in a key value engine prefixed with `alice/` while granting \"bob\" access to `bob/`, \"carol\" access to `carol/`, etc.\n\nIf the data used in the template can be controlled by an attacker (e.g. your system allows the user to freely select their username) and \"globbing\" characters are considered valid ( e.g. `*` is a valid username) they will be able to escalate their privileges.\n\nThe problematic characters are `*`, `+` and `/`.\n\n### PKI Secrets Engine `allowed_uri_sans_template` and `allowed_domains` Polices\n\nThe PKI secrets engine allows you to limit the \"common names\" a user can requests a TLS certificate for. Similar to the ACL polices this allows you to restrict e.g. \"alice\" to  `alice.example.com`, \"bob\" to  `bob.example.com`, etc. via templates.\n\nAgain, if an attacker can control this data freely, they can trick the PKI engine into using e.g. the `*.example.com` glob effectively allowing them to issue certificates for any subdomain of `example.com`\n\nThe problematic character in this case is `*`.\n\n### SSH Secrets Engine `allowed_users` and `allowed_domains` Polices\n\nThe SSH secrets engine allows you to limit the \"principal\" a user can request as SSH certificate for. Similar to ACL and PKI, this allows templates.\n\nThe problematic character in this case is `,` as the template result is split at all commas and each entry will be allowed.\n\n## Am I affected?\n\nYou are affected, if a) you use a templated policy (ACL, PKI or SSH) and b) your users can modify data used by your template freely.\n\nIf you can guarantee that the data used in your templates will never contain the problematic characters, you are not affected. For example, if you use `{{ identity.entity.id }}` in your policy, you are not affected, because `identity.entity.id` is randomly generated by OpenBao.\n\n\n\nEven with this vulnerability patched: Using user controllable data in your policies is probably not the best idea.\n\n## Patches\n\nAll three have been patched in OpenBao v2.6.0.","aliases":["CVE-2026-71543"],"modified":"2026-09-22T21:00:07.697260675Z","published":"2026-09-22T20:36:49Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-09-22T20:36:49Z","nvd_published_at":"2026-09-21T15:17:31Z","cwe_ids":["CWE-863"]},"references":[{"type":"WEB","url":"https://github.com/openbao/openbao/security/advisories/GHSA-59w7-v8rr-pr4p"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-71543"},{"type":"WEB","url":"https://github.com/openbao/openbao/pull/3401"},{"type":"WEB","url":"https://github.com/openbao/openbao/pull/3473"},{"type":"WEB","url":"https://github.com/openbao/openbao/commit/2d4ebafec5c524408b3d4ac1198df909cb7ac8c1"},{"type":"WEB","url":"https://github.com/openbao/openbao/commit/e516ce508e1481504cadbfbf62052364339093bc"},{"type":"WEB","url":"https://github.com/hashicorp/vault/blob/main/CHANGELOG.md#201"},{"type":"PACKAGE","url":"https://github.com/openbao/openbao"},{"type":"WEB","url":"https://github.com/openbao/openbao/releases/tag/v2.6.0"}],"affected":[{"package":{"name":"github.com/openbao/openbao","ecosystem":"Go","purl":"pkg:golang/github.com/openbao/openbao"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.0.0-20260710001938-2d4ebafec5c5"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-59w7-v8rr-pr4p/GHSA-59w7-v8rr-pr4p.json"}},{"package":{"name":"github.com/openbao/openbao","ecosystem":"Go","purl":"pkg:golang/github.com/openbao/openbao"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.1.0"},{"last_affected":"1.1.5"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-59w7-v8rr-pr4p/GHSA-59w7-v8rr-pr4p.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}