CVE-2026-40214 PUBLISHED

Assigner: mitre
Reserved: 10.04.2026 Published: 07.05.2026 Updated: 07.05.2026

In OpenStack Cyborg before 16.0.1, the Accelerator Request (ARQ) API does not enforce project ownership at any layer. The project_id column in the database is never populated (NULL for every ARQ), database queries have no project filtering, and policy checks are self-referential (the authorize_wsgi decorator compares the caller's project_id with itself rather than the target resource). Any authenticated non-admin user can complete various actions such as deleting ARQs bound to other projects' instances, aka cross-tenant denial of service.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CVSS Score: 6.3

Product Status

Vendor OpenStack
Product Cyborg
Versions Default: unaffected
  • affected from 3.0.0 to 14.0.1 (excl.)
  • affected from 15.0.0 to 15.0.1 (excl.)
  • affected from 16.0.0 to 16.0.1 (excl.)

References

Problem Types

  • CWE-282 Improper Ownership Management CWE