CVE-2026-55707 PUBLISHED

Assigner: mitre
Reserved: 17.06.2026 Published: 05.08.2026 Updated: 05.08.2026

In OpenStack Neutron before 28.0.2, the subnetpool onboarding API does not verify ownership of the target subnets. An authenticated user can onboard subnets from another project's shared network into their own subnetpool, mutating the victim's subnet state and altering L3 routing and address scope behavior for victim routers.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N
CVSS Score: 7.1

Product Status

Vendor OpenStack
Product Neutron
Versions Default: unaffected
  • affected from 14.0.0 to 26.0.6 (excl.)
  • affected from 27.0.0 to 27.0.4 (excl.)
  • affected from 28.0.0 to 28.0.2 (excl.)

References

Problem Types

  • CWE-863 Incorrect Authorization CWE