PT-2026-38596 · Openstack · Openstack Cyborg

Sean Mooney

·

Published

2026-05-07

·

Updated

2026-05-09

·

CVE-2026-40213

CVSS v3.1

7.4

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions OpenStack Cyborg versions prior to 16.0.1
Description Multiple API endpoints use rule:allow (check str='@') as the default policy, which unconditionally authorizes any request containing a valid Keystone token. This occurs regardless of the user's roles, project membership, or scope. Consequently, an authenticated user with no assigned roles can perform various actions, including reprogramming FPGA (Field Programmable Gate Array) bitstreams on arbitrary compute nodes via agent RPC (Remote Procedure Call).
Recommendations Update to version 16.0.1.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-40213
GHSA-MM7J-MHHJ-HJ36

Affected Products

Openstack Cyborg