Search CVE reports


Toggle filters

1 – 2 of 2 results


CVE-2026-40214

Medium priority
Fixed

In OpenStack Cyborg before 16.0.1, the Accelerator Request (ARQ) API does not enforce project ownership at any layer. The project_id column in the database is never populated (NULL for every ARQ), database queries have no project...

1 affected package

cyborg

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cyborg Fixed Not in release Not in release
Show less packages

CVE-2026-40213

Medium priority
Fixed

OpenStack Cyborg before 16.0.1 uses rule:allow (check_str='@') as the default policy for multiple API endpoints. This unconditionally authorizes any request carrying a valid Keystone token regardless of roles, project membership,...

1 affected package

cyborg

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cyborg Fixed Not in release Not in release
Show less packages