Description
In OpenStack Zaqar before 23.0.1, the WebSocket transport fails to bind the project identifier in subsequent requests to the project authenticated by the Keystone token. An authenticated user with a valid token for one project may substitute another project's UUID to enumerate, inspect, create, or delete queues belonging to that project, resulting in unauthorized disclosure, modification, or loss of queue data. Only deployments using the WebSocket transport with Keystone authentication are affected.
Published: 2026-10-07
Score: 6.1 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Openstack
Openstack zaqar
Vendors & Products Openstack
Openstack zaqar

Wed, 07 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Description In OpenStack Zaqar before 23.0.1, the WebSocket transport fails to bind the project identifier in subsequent requests to the project authenticated by the Keystone token. An authenticated user with a valid token for one project may substitute another project's UUID to enumerate, inspect, create, or delete queues belonging to that project, resulting in unauthorized disclosure, modification, or loss of queue data. Only deployments using the WebSocket transport with Keystone authentication are affected.
Weaknesses CWE-472
References
Metrics cvssV4_0

{'score': 6.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-10-07T20:38:56.097Z

Reserved: 2026-10-07T20:08:46.682Z

Link: CVE-2026-107363

cve-icon Vulnrichment

Updated: 2026-10-07T20:36:13.985Z

cve-icon NVD

Status : Received

Published: 2026-10-07T21:17:15.690

Modified: 2026-10-07T21:17:15.690

Link: CVE-2026-107363

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T21:30:17Z

Weaknesses
  • CWE-472

    External Control of Assumed-Immutable Web Parameter