OpenBao PostgreSQL Database Secrets Engine SQL Injection Vulnerability

Vulnerability

A SQL injection vulnerability has been identified in OpenBao versions through 2.5.2, specifically within the PostgreSQL database secrets engine. The issue arises when OpenBao revokes privileges on a role, as it fails to properly quote schema names. This flaw can lead to unsuccessful role revocations or, in rare cases, allow SQL injection as the management user.

Impact

Exploitation of this vulnerability could result in SQL injection, allowing an attacker to execute arbitrary SQL commands in the context of the database management user.

Remediation

Users can upgrade to OpenBao version 2.5.3, where this vulnerability has been patched. As an additional step, it is recommended to audit table schemas and ensure that database users do not have the ability to create new schemas and grant privileges on them.

Added: Apr 21, 2026, 1:18 AM
Updated: Apr 21, 2026, 1:18 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
4.4
remediation
0.0
relevance
6.4
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.