CVE-2026-55748 PUBLISHED

Assigner: mitre
Reserved: 17.06.2026 Published: 17.06.2026 Updated: 17.06.2026

OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:L
CVSS Score: 6

Product Status

Vendor OpenStack
Product Horizon
Versions Default: unaffected
  • affected from 8.0.0 to 25.3.3 (excl.)
  • affected from 25.4.0 to 25.5.3 (excl.)
  • affected from 25.6.0 to 25.7.4 (excl.)

References

Problem Types

  • CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CWE