4.3
CVE-2026-74248
- EPSS 0.19%
- Veröffentlicht 14.08.2026 20:20:31
- Zuletzt bearbeitet 17.08.2026 21:16:49
- CVE-Watchlists
- Unerledigt
OpenStack Octavia through 18.0.0 mishandles quality of service (QoS) policy authorization. By associating another project's QoS policy with an amphora, an authenticated user may prevent deletion of that policy. All Octavia deployments are affected.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerOpenStack
≫
Produkt
Octavia
Default Statusunaffected
Version
0
Version <
16.0.2
Status
affected
Version
17.0.0
Status
affected
Version
18.0.0
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.19% | 0.089 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| MITRE | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
|
CWE-863 Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
https://bugs.launchpad.net/octavia/+bug/2161500
https://www.openwall.com/lists/oss-security/2026/08/13/12
http://www.openwall.com/lists/oss-security/2026/08/17/2