
Critical RCE Alert: Full takeover of HashiCorp Vault and OpenBao
securityvulnerabilityRCEHashiCorpVaultOpenBaoexploitpatchcybersecurity
OpenBao engineers at ControlPlane have chained 4 vulnerabilities that allow complete compromise of an OpenBao or Vault server from an unauthenticated position under certain conditions, requiring only an unauthenticated entry path and a defined Raft snapshot policy. This is the second RCE ever found in the Vault codebase. OpenBao has been patched in versions 2.6.3 and 2.7.0, but HashiCorp Vault remains exposed as IBM did not coordinate a mutual disclosure policy, leaving Vault users without an official mitigation.