PT-2026-67950 · Openstack · Openstack Neutron
CVE-2026-55707
·
Published
2026-08-05
·
Updated
2026-08-12
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenStack Neutron versions prior to 28.0.2
Description
The subnetpool onboarding API fails to verify the ownership of target subnets. This allows an authenticated user to onboard subnets belonging to another project's shared network into their own subnetpool. Such an action can mutate the subnet state of the victim and alter the L3 routing and address scope behavior for the victim's routers.
Recommendations
Update OpenStack Neutron to version 28.0.2 or later.
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openstack Neutron