CVE-2026-40213

HIGH

OpenStack Cyborg < 14.0.1, 15.0.0-15.0.1, 16.0.0-16.0.1 - Authenticated Incorrect Authorization via Default Policy Rule

Title source: llm
STIX 2.1

Description

OpenStack Cyborg before 16.0.1 uses rule:allow (check_str='@') as the default policy for multiple API endpoints. This unconditionally authorizes any request carrying a valid Keystone token regardless of roles, project membership, or scope. An authenticated user with zero role assignments can complete various actions such as reprogramming FPGA bitstreams on arbitrary compute nodes via agent RPC.

Scores

CVSS v3 7.4
EPSS 0.0004
EPSS Percentile 11.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (4)
OpenStack/Cyborg 15.0.0 - 15.0.1
OpenStack/Cyborg 16.0.0 - 16.0.1
OpenStack/Cyborg 5.0.0 - 14.0.1
pypi/openstack-cyborg 0 - 16.0.1PyPI
Published May 07, 2026
Tracked Since May 08, 2026