{"id":"CVE-2025-64761","aliases":["BIT-openbao-2025-64761","GHSA-7ff4-jw48-3436","GO-2025-4156"],"url":"https://o3.security/vulnerability/CVE-2025-64761","summary":"OpenBao Privileged Operator Identity Group Root Escalation","details":"OpenBao is an open source identity-based secrets management system. Prior to version 2.4.4, a privileged operator could use the identity group subsystem to add a root policy to a group identity group, escalating their or another user's permissions in the system. Specifically this is an issue when: an operator in the root namespace has access to identity/groups endpoints and an operator does not have policy access. Otherwise, an operator with policy access could create or modify an existing policy to grant root-equivalent permissions through the sudo capability. This issue has been patched in version 2.4.4.","published":"2025-11-25T00:01:17.986Z","modified":"2026-08-12T03:51:13.429247159Z","cvss":null,"epss":{"score":0.00352,"percentile":0.28498,"asOf":"2026-08-20"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/openbao/openbao","fixedVersion":"2.4.4"}],"fix":{"url":"https://github.com/openbao/openbao/commit/16bb0ccd37a502930a289d434cbe4e7b4edd66e5","label":"openbao/openbao@16bb0cc"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/64xxx/CVE-2025-64761.json"},{"type":"ADVISORY","url":"https://github.com/openbao/openbao/security/advisories/GHSA-7ff4-jw48-3436"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-64761"},{"type":"FIX","url":"https://github.com/openbao/openbao/commit/16bb0ccd37a502930a289d434cbe4e7b4edd66e5"},{"type":"FIX","url":"https://github.com/openbao/openbao/pull/2143"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:13.429247159Z"}}