OpenBao/Vault: unauth→RCE exploit chain — GHSA-j6wc snapshot RCE CVSSv4 9.4; fix OpenBao 2.6.3 / 2.7.0 (Vault patch pending)
ControlPlane (28 September 2026), with the OpenBao community, describes a full exploit chain from unauthenticated access to remote code execution in OpenBao (and notes the same class of issues affect HashiCorp Vault / IBM remediation still pending at publication). The chain combines multiple independently reported issues patched in OpenBao v2.6.3 and v2.7.0 (shipped 23 Sep 2026), including GHSA-j6wc-jpvg-xfxq — Critical CVSSv4 9.4 remote code execution via Raft snapshot restore / plugin-catalog replacement (Raft storage backend; privileged snapshot endpoints; original to HashiCorp Vault) — plus High issues GHSA-x8fg-h69x-p28f (PKI ACME validation bypass, 8.2), GHSA-mjch-vcw3-hhmf (cross-namespace policy access, 7.7), and GHSA-fg5x-7whg-6c28 (ACL deny bypass via non-canonical URLs, 7.6). ControlPlane: second-ever remote code execution vulnerability class in Vault/OpenBao; fork-coordination gaps can leave customers exposed. Operators not using Raft storage are not affected by the snapshot RCE path per GHSA-j6wc. Desk does not reproduce the chain. Primary advisory: OpenBao GHSA-j6wc; narrative: ControlPlane 28 Sep.
- Product
- OpenBao (Raft storage) / HashiCorp Vault (IBM — remediation pending per ControlPlane)
- Versions
- OpenBao affected <2.6.3 on Raft path for GHSA-j6wc; patched 2.6.3 and 2.7.0 (23 Sep 2026). Vault: watch IBM/HashiCorp advisories — ControlPlane states post will update when Vault remediates.
- CVSS
- (CVSSv4 — GHSA-j6wc-jpvg-xfxq); also 8.2 / 7.7 / 7.6 (related GHSAs in same release)
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H (GHSA-J6WC ALONE; CHAIN USES ADDITIONAL HIGH GHSAS FOR EARLIER FOOTHOLD) - Exploited in Australia?
- unknown
- Patch to
- Upgrade OpenBao to 2.6.3+ or 2.7.0+ immediately if Raft storage is in use; review exposure of snapshot / PKI ACME / identity ACL paths; rotate secrets and plugin trust assumptions if compromise suspected. Vault operators: track IBM/HashiCorp security advisories for the matching fixes and apply when published. Prefer ControlPlane + GHSA for defender context — do not treat magazine amplifications as the patch source.
Primary: OpenBao GHSA-j6wc-jpvg-xfxq — RCE via Raft snapshot-force / plugin catalog (Critical CVSSv4 9.4; patched 2.6.3 / 2.7.0) · Vendor: OpenBao security advisory GHSA-j6wc-jpvg-xfxq (vendor primary) · ControlPlane — A Realistic Code Execution Exploit Chain in OpenBao and Vault (28 Sep 2026)
