# OpenBao Patches RCE While Vault Remains Exposed

A security alert describes a plausible unauthenticated remote-code-execution path that could allow full server compromise of OpenBao or HashiCorp Vault when specific entry-path and Raft snapshot-policy conditions are present. OpenBao addressed the issue in versions 2.6.3 and 2.7.0; the post said HashiCorp Vault had no official mitigation at the time. Its claim that IBM was responsible for the absence of coordinated disclosure is uncorroborated in the supplied discussion.

- Government IT teams and contractors should identify whether their environments run OpenBao or Vault and assess whether the described access and snapshot-policy conditions apply.
- Operators of affected OpenBao deployments can upgrade to version 2.6.3 or 2.7.0, as applicable. The supplied signal identifies no official Vault mitigation, so it does not support a specific Vault remediation recommendation.
- Procurement teams and service providers should account for the differing patch status when assessing secrets-management tools used in managed services, infrastructure, and contractor environments.

**Jurisdictions:** federal
**Industries:** Information Technology
**Topics:** Cybersecurity
**Published:** September 29, 2026

### Vendors
- HashiCorp ()
- IBM ()
- ControlPlane ()

### Key Quotes
> If you are impacted, upgrade as soon as possible to OpenBao 2.6.3 or 2.7.0.
> — Original poster

### Sources
- [Critical RCE Alert: Full takeover of HashiCorp Vault and OpenBao. OpenBao is patched. Vault remains exposed](https://www.reddit.com/r/cybersecurity/comments/1wtn2bh/critical_rce_alert_full_takeover_of_hashicorp) - reddit-cybersecurity