CVE-2026-76878
Last modified
CVE-2026-76878 is a high-severity vulnerability rated 8.4/10 on the CVSS scale. In OpenStack Aodh before 22.0.1, the alarm list API bypasses project scoping when the all_projects query parameter is set to false. The API checks for the presence of the all_projects key rather than its value; a true value enforces the administrator-only policy, but a false value removes the key and skips the branch that normally restricts results to the caller's project. EPSS estimates a 0.39% chance of exploitation in the next 30 days.
Description
In OpenStack Aodh before 22.0.1, the alarm list API bypasses project scoping when the all_projects query parameter is set to false. The API checks for the presence of the all_projects key rather than its value; a true value enforces the administrator-only policy, but a false value removes the key and skips the branch that normally restricts results to the caller's project. A non-admin user with the reader role can list alarms from all projects, exposing alarm actions containing trust webhook URLs, Heat signal endpoints, project IDs, and user IDs. The parameter can also be combined with a foreign project_id to target a specific project's alarms. A related concern is that OpenStack Watcher does not apply authorization to its webhook trigger endpoint. Any authenticated user who learns an audit's webhook URL, for example from this leaked Aodh alarm metadata, can start an EVENT audit and its associated action plan regardless of their own project or role. The webhook endpoint has lacked policy enforcement since its introduction in the Ussuri release (Watcher 4.0.0).
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| OpenStack | Aodh | >= 10.0.0, < 20.0.1; >= 21.0.0, < 21.0.1; >= 22.0.0, < 22.0.1 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-76878?
How severe is CVE-2026-76878?
How do I fix CVE-2026-76878?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-76848TypeORM's SelectQueryBuilder.distinctOn accepts an array of …7.5
- CVE-2026-7685A vulnerability was detected in Edimax BR-6208AC up to 1.02.…8.8
- CVE-2026-76850LMDeploy deserializes disaggregated-serving peer messages wi…9.8
- CVE-2026-7686A vulnerability was found in eyeo Adblock Plus up to 4.36.2 …5.5
- CVE-2026-7687A vulnerability was determined in langflow-ai langflow up to…6.3
- CVE-2026-76876Craftplan before 0.5.1 contains a broken access control vuln…5.9
- CVE-2026-76879C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 …7.5
- CVE-2026-7688A vulnerability was identified in Dolibarr ERP CRM up to 23.…5
- CVE-2026-76880RRC protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to …7.5
- CVE-2026-76881CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to …4.7
- CVE-2026-76882Bluetooth Attribute Protocol dissector crash in 4.6.0 to 4.6…4.7
- CVE-2026-76883Catapult DCT2000 file parser crash in 4.6.0 to 4.6.7 and 4.4…4.7
Are you affected by CVE-2026-76878?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
