In OpenStack Zaqar before 23.0.1, the WebSocket transport fails to bind the project identifier in subsequent requests to the project authenticated by the Keystone token. An authenticated user with a valid token for one project may substitute another project's UUID to enumerate, inspect, create, or delete queues belonging to that project, resulting in unauthorized disclosure, modification, or loss of queue data. Only deployments using the WebSocket transport with Keystone authentication are affected.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 08 Oct 2026 00:30:00 +0000

Type Values Removed Values Added
References

Wed, 07 Oct 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Openstack
Openstack zaqar
Vendors & Products Openstack
Openstack zaqar

Wed, 07 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Description In OpenStack Zaqar before 23.0.1, the WebSocket transport fails to bind the project identifier in subsequent requests to the project authenticated by the Keystone token. An authenticated user with a valid token for one project may substitute another project's UUID to enumerate, inspect, create, or delete queues belonging to that project, resulting in unauthorized disclosure, modification, or loss of queue data. Only deployments using the WebSocket transport with Keystone authentication are affected.
Weaknesses CWE-472
References
Metrics cvssV4_0

{'score': 6.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-10-07T23:06:46.671Z

Reserved: 2026-10-07T20:08:46.682Z

Link: CVE-2026-107363

cve-icon Vulnrichment

Updated: 2026-10-07T23:06:46.671Z

cve-icon NVD

Status : Received

Published: 2026-10-07T21:17:15.690

Modified: 2026-10-08T00:16:34.973

Link: CVE-2026-107363

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T21:45:06Z

Weaknesses