PT-2026-44555 · Openstack · Openstack Neutron

·

CVE-2026-49299

·

Published

2026-05-28

·

Updated

2026-07-21

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenStack Neutron versions 26.0.0 through 28.0.0
Description The tagging controller enforces plural policy action names on single-tag write operations, whereas the defined policy rules use singular names. This mismatch causes the default policy to evaluate the actions as allowed, enabling a project reader to create and update tags on resources within the same project.
Recommendations Update to version 28.0.1.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-49299
GHSA-XV24-HXH9-2HH9
PYSEC-2026-2678

Affected Products

Openstack Neutron