CVE-2026-40213
HIGHCVSS 7.4/10EPSS 0.21%
Last modified
This CVE is reserved or awaiting analysis. Details will appear once published by NVD.
Description
OpenStack Cyborg before 16.0.1 uses rule:allow (check_str='@') as the default policy for multiple API endpoints. This unconditionally authorizes any request carrying a valid Keystone token regardless of roles, project membership, or scope. An authenticated user with zero role assignments can complete various actions such as reprogramming FPGA bitstreams on arbitrary compute nodes via agent RPC.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Are you affected by CVE-2026-40213?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
