LiveActive security incident?Get immediate response
CVE Record

CVE-2026-33757: OpenBao lacks user confirmation for OIDC direct callback mode

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.2, OpenBao does not prompt for user confirmation when logging in via JWT/OIDC and a role with `callback_mode` set to `direct`. This allows an attacker to start an authentication request and perform "remote phishing" by having the victim visit the URL and automatically log-in to the session of the attacker. Despite being based on the authorization code flow, the `direct` mode calls back directly to the API and allows an attacker to poll for an OpenBao token until it is issued. Version 2.5.2 includes an additional confirmation screen for `direct` type logins that requires manual user interaction in order to finish the authentication. This issue can be worked around either by removing any roles with `callback_mode=direct` or enforcing confirmation for every session on the token issuer side for the Client ID used by OpenBao.

CriticalCVSS 9.6Not KEV-listedUpdated
Glexia's TakeAutomated analysiscritical

Security readout for executives and security teams

Plain-English summary

OpenBao versions before 2.5.2 can let a phished user unknowingly complete login into an attacker-controlled session when JWT/OIDC direct callback mode is enabled. Because OpenBao protects secrets, a stolen token could create serious confidentiality and integrity risk depending on assigned policies.

Executive priority

Treat as urgent for environments using OpenBao OIDC/JWT login. Prioritize secrets-management platforms because compromised tokens can expose sensitive systems. Confirm whether direct callback roles exist before assuming exposure.

Technical view

The issue affects OpenBao before 2.5.2 when a JWT/OIDC role uses callback_mode=direct. Direct callback mode did not require user confirmation, allowing remote phishing where a victim completes authentication and OpenBao issues a token to the attacker's pending session. Version 2.5.2 adds a manual confirmation screen.

Likely exposure

Exposure is limited to OpenBao deployments before 2.5.2 with JWT/OIDC roles configured with callback_mode=direct. Impact depends on the victim's OpenBao policies and token privileges. The source bundle does not identify affected downstream packages beyond OpenBao.

Exploitation context

The vulnerability is network reachable, low complexity, and requires user interaction. The provided sources do not show CISA KEV listing or confirmed active exploitation. The described attack is phishing-based rather than unauthenticated direct token theft.

Researcher notes

This is mapped to CWE-384 and resembles session binding failure in an authorization-code-style flow. RFC8628 section 5.4 is referenced for user confirmation expectations. The fix adds confirmation for direct logins; review commit e32103951925723e9787e33886ab6b6ec20f4964 for implementation detail.

Mitigation direction

  • Upgrade OpenBao to version 2.5.2 or later.
  • Remove or disable roles using callback_mode=direct.
  • Enforce issuer-side confirmation for every OpenBao Client ID session.
  • Review vendor and downstream guidance for package-specific remediation status.

Validation and detection

  • Inventory OpenBao deployments and confirm versions are 2.5.2 or later.
  • Review JWT/OIDC auth roles for callback_mode=direct.
  • Confirm direct-mode login presents a manual confirmation screen.
  • Check identity provider policy for mandatory confirmation on the OpenBao client.
Prepared
Confidence
high
Sources
8

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · low confidence lookup

CWE-384: Exact CWE lookup

Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
description · low confidence lookup

Credential and access behavior lookup

The CVE wording references authentication or credential exposure, so valid-account and credential-access review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2026-33757 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Critical
CVSS
9.6 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

2CVSS vectors
5Timeline events
2ADP providers
7Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: total

CVSS vector scores

2 official scores

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
9.6CVSS 3.1CriticalCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L2.86GitHub_M
9.6CVSS 3.1CriticalCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L2.86redhat-SADP

Vulnerability scoring details

Base CVSS 3.1 score

9.6Critical
CVSS 3.1 vector shape for CVE-2026-33757Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. ADP timelineredhat-SADP

    Made public.

  3. CVE publishedCVE Program

    The CVE record was published.

  4. ADP timelineredhat-SADP

    Reported to Red Hat.

  5. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
other:ssvc
redhat-SADPOpenBao: lack of user confirmation for OpenBao OIDC direct callback mode
other:Red Hat severity ratingcvssV3_1
  • 2026-03-27T15:01:52.669Z: Reported to Red Hat.
  • 2026-03-27T14:10:58.639Z: Made public.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
openbaoopenbao< 2.5.2Listed
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-384 · source CWE mapping

Session Fixation

Session Fixation represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.