logo

Critical 9.6 CVSS OIDC Flaws in OpenBao Turn “Direct Login” Into a Phishing Trap

ID: dad2ada5-cea0-56ea-bcf1-6839d6e3d699

STIX ID: report--dad2ada5-cea0-56ea-bcf1-6839d6e3d699

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-03-30

Date Updated: 2026-04-23

Author: Ddos

...
...

OpenBao released version 2.5.2 to fix two critical OIDC/JWT issues: CVE-2026-33757 (CVSS 9.6) enables an attacker to trick users into automatic login when callback_mode=direct and poll for authentication tokens (session hijack), and CVE-2026-33758 (CVSS 9.4) is a reflected XSS via error_description that can expose Web UI tokens; mitigations include disabling direct mode and enforcing issuer confirmation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.