← Späť na vyhľadávanie CVE

CVE-2026-40214

OpenStack Cyborg

Popis

In OpenStack Cyborg before 16.0.1, the Accelerator Request (ARQ) API does not enforce project ownership at any layer. The project_id column in the database is never populated (NULL for every ARQ), database queries have no project filtering, and policy checks are self-referential (the authorize_wsgi decorator compares the caller-s project_id with itself rather than the target resource). Any authenticated non-admin user can complete various actions such as deleting ARQs bound to other projects- instances, aka cross-tenant denial of service.

CVSS 6.3EPSS 0.20600000000000002%Riziko 0.64
Zobraziť zdroj
Zverejnené
2026-05-07 22:16:35
Dotknuté verzie
<16.0.1
Typ
Core software
Vektor
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L