PT-2026-38596 · Openstack · Openstack Cyborg

·

CVE-2026-40213

·

Published

2026-05-07

·

Updated

2026-07-13

CVSS v3.1

7.4

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions OpenStack Cyborg versions prior to 16.0.1
Description Multiple API endpoints use rule:allow (check str='@') as the default policy, which unconditionally authorizes any request containing a valid Keystone token. This occurs regardless of the user's roles, project membership, or scope. Consequently, an authenticated user with no assigned roles can perform various actions, including reprogramming FPGA (Field Programmable Gate Array) bitstreams on arbitrary compute nodes via agent RPC (Remote Procedure Call).
Recommendations Update to version 16.0.1.

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40213
GHSA-MM7J-MHHJ-HJ36
PYSEC-2026-2853
USN-8413-1

Affected Products

Openstack Cyborg