Critical 9.6 CVSS OIDC Flaws in OpenBao Turn “Direct Login” Into a Phishing Trap
ID: dad2ada5-cea0-56ea-bcf1-6839d6e3d699
STIX ID: report--dad2ada5-cea0-56ea-bcf1-6839d6e3d699
Feed Name: securityonline.info
Threat Score
OpenBao released version 2.5.2 to fix two critical OIDC/JWT issues: CVE-2026-33757 (CVSS 9.6) enables an attacker to trick users into automatic login when callback_mode=direct and poll for authentication tokens (session hijack), and CVE-2026-33758 (CVSS 9.4) is a reflected XSS via error_description that can expose Web UI tokens; mitigations include disabling direct mode and enforcing issuer confirmation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
