CVE-2026-40213

EUVD-2026-28455
OpenStack Cyborg before 16.0.1 uses rule:allow (check_str='@') as the default policy for multiple API endpoints. This unconditionally authorizes any request carrying a valid Keystone token regardless of roles, project membership, or scope. An authenticated user with zero role assignments can complete various actions such as reprogramming FPGA bitstreams on arbitrary compute nodes via agent RPC.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.4 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 10.83%
Debian logo
Debian Releases
Debian Product
Codename
cyborg
forky
16.0.0+git+2026.04.26.b8edfa06f1-1
fixed
sid
16.0.0+git+2026.04.26.b8edfa06f1-1
fixed
trixie
14.0.0-3+deb13u1
fixed
trixie (security)
14.0.0-3+deb13u1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
cyborg
jammy
dne
noble
dne
questing
Fixed 14.0.0-3+deb13u1build0.25.10.1
released
resolute
Fixed 16.0.0-2ubuntu0.1
released