CVE-2026-84165 PUBLISHED

Lack of authorisation in OpenNebula by OpenNebula Systems

Assigner: INCIBE
Reserved: 01.09.2026 Published: 01.09.2026 Updated: 01.09.2026

A vulnerability relating to incorrect access control in OpenNebula by OpenNebula Systems, affecting all versions prior to 7.4. This vulnerability could allow an authenticated user with basic permissions to execute commands on virtual machines belonging to other users via the one.vm.exec function, without proper verification of access permissions. To exploit the vulnerability, it is only necessary to know the virtual machine’s identifier and for qemu-agent to be enabled on that machine. Exploitation could allow commands to be executed and compromise the confidentiality, integrity and availability of the affected virtual machines.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor OpenNebula Systems
Product OpenNebula
Versions Default: unaffected
  • affected from 0 to 7.4 (excl.)

Solutions

Update to OpenNebula version 7.4.

Credits

  • Yonghwa Lee, Xint from Theori. finder

References

Problem Types

  • CWE-284 Improper Access Control CWE