Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4

Количество 4

ubuntu логотип

CVE-2026-40213

3 месяца назад

OpenStack Cyborg before 16.0.1 uses rule:allow (check_str='@') as the default policy for multiple API endpoints. This unconditionally authorizes any request carrying a valid Keystone token regardless of roles, project membership, or scope. An authenticated user with zero role assignments can complete various actions such as reprogramming FPGA bitstreams on arbitrary compute nodes via agent RPC.

CVSS3: 7.4
EPSS: Низкий
nvd логотип

CVE-2026-40213

3 месяца назад

OpenStack Cyborg before 16.0.1 uses rule:allow (check_str='@') as the default policy for multiple API endpoints. This unconditionally authorizes any request carrying a valid Keystone token regardless of roles, project membership, or scope. An authenticated user with zero role assignments can complete various actions such as reprogramming FPGA bitstreams on arbitrary compute nodes via agent RPC.

CVSS3: 7.4
EPSS: Низкий
debian логотип

CVE-2026-40213

3 месяца назад

OpenStack Cyborg before 16.0.1 uses rule:allow (check_str='@') as the ...

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-mm7j-mhhj-hj36

3 месяца назад

OpenStack Cyborg uses rule:allow (check_str='@') as the default policy for multiple API endpoints

CVSS3: 7.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-40213

OpenStack Cyborg before 16.0.1 uses rule:allow (check_str='@') as the default policy for multiple API endpoints. This unconditionally authorizes any request carrying a valid Keystone token regardless of roles, project membership, or scope. An authenticated user with zero role assignments can complete various actions such as reprogramming FPGA bitstreams on arbitrary compute nodes via agent RPC.

CVSS3: 7.4
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-40213

OpenStack Cyborg before 16.0.1 uses rule:allow (check_str='@') as the default policy for multiple API endpoints. This unconditionally authorizes any request carrying a valid Keystone token regardless of roles, project membership, or scope. An authenticated user with zero role assignments can complete various actions such as reprogramming FPGA bitstreams on arbitrary compute nodes via agent RPC.

CVSS3: 7.4
0%
Низкий
3 месяца назад
debian логотип
CVE-2026-40213

OpenStack Cyborg before 16.0.1 uses rule:allow (check_str='@') as the ...

CVSS3: 7.4
0%
Низкий
3 месяца назад
github логотип
GHSA-mm7j-mhhj-hj36

OpenStack Cyborg uses rule:allow (check_str='@') as the default policy for multiple API endpoints

CVSS3: 7.4
0%
Низкий
3 месяца назад

Уязвимостей на страницу