Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 07 Oct 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openstack
Openstack zaqar |
|
| Vendors & Products |
Openstack
Openstack zaqar |
Wed, 07 Oct 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 07 Oct 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In OpenStack Zaqar before 23.0.1, the WebSocket transport fails to bind the project identifier in subsequent requests to the project authenticated by the Keystone token. An authenticated user with a valid token for one project may substitute another project's UUID to enumerate, inspect, create, or delete queues belonging to that project, resulting in unauthorized disclosure, modification, or loss of queue data. Only deployments using the WebSocket transport with Keystone authentication are affected. | |
| Weaknesses | CWE-472 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-10-07T20:38:56.097Z
Reserved: 2026-10-07T20:08:46.682Z
Link: CVE-2026-107363
Updated: 2026-10-07T20:36:13.985Z
Status : Received
Published: 2026-10-07T21:17:15.690
Modified: 2026-10-07T21:17:15.690
Link: CVE-2026-107363
No data.
OpenCVE Enrichment
Updated: 2026-10-07T21:45:06Z
-
CWE-472
External Control of Assumed-Immutable Web Parameter